T09 · Insecure Skill Coding Practices
- Location
scripts/elizacloud-client.sh:9- Finding
API Key Can Be Transmitted to an Arbitrary Configurable Host
- Content
View full analysis
- Remediation
View remediation
Security audit
Security checks for vulnerabilities and agentic risk
This elizaOS Cloud skill appears purpose-aligned, but it should be reviewed because it uses a powerful API key for cloud changes and billing-related actions without tight safeguards.
Install only if you trust elizaOS Cloud and will use a narrowly scoped API key. Avoid sending secrets or regulated data in chat, image, knowledge, or A2A payloads; require explicit approval for deletes, billing changes, top-ups, API-key creation, and public/discoverable agent registration. Do not set `ELIZACLOUD_BASE_URL` except to a trusted HTTPS elizaOS endpoint, and prefer a pinned or local CLI install over the optional unpinned global install.
scripts/elizacloud-client.sh:9API Key Can Be Transmitted to an Arbitrary Configurable Host
SKILL.md:274Optional Installation Uses an Unpinned Global Dependency
The code is clearly related to elizaOS Cloud and accurately uses the declared API key and service domain, so the general service association is correct. However, the declared description materially overstates the implemented functionality. The script only supports status checking, basic agent CRUD, chat completions, and image generation. There is no code for video generation, voice cloning, knowledge base operations, container management, marketplace features, or broader cloud-hosted agent deployment/management workflows. Because the description presents a substantially broader capability set than the code actually provides, this is a description-behavior mismatch.
The documented DELETE endpoint enables destructive actions against cloud-hosted agents and accepts a path parameter that could be driven directly by model-controlled or user-supplied input. In agent environments, this is dangerous because ambiguous prompts, prompt injection, or parameter confusion could trigger irreversible deletion of resources without adequate validation or confirmation.
Delete Agent
DELETE /api/my-agents/characters/{id}
The skill documents shell-based operations but does not declare any tool scope such as allowed-tools or permissions. That omission weakens execution boundaries and makes it easier for an agent runtime or reviewer to underestimate that the skill can invoke networked shell commands against an external API using sensitive credentials.
Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.
curl https://elizacloud.ai/api/v1/chat/completions \
-H "Authorization: Bearer $ELIZACLOUD_API_KEY" \
-H "Content-Type: application/json" \
-d '{
The skill includes destructive and cost-incurring operations such as deleting agents, creating API keys, purchasing credits, and enabling auto top-up without prominent warnings or confirmation requirements. In an agent setting, documenting these actions as routine can lead to accidental state changes, financial loss, or service disruption if a model executes them from ambiguous user prompts.
Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.
# 1. Create agent
curl -X POST https://elizacloud.ai/api/v1/app/agents \
-H "Authorization: Bearer $ELIZACLOUD_API_KEY" \
-d '{"name": "Support Bot", "bio": "Customer support specialist"}'
This markdown file documents API usage that posts user message content to a remote service, but the surrounding text does not warn readers that prompts and other supplied data will be transmitted off-system. Under the markdown-file criteria for missing user warnings, externally sending user data should be disclosed when privacy or system integrity may be affected.
Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.
All API requests require authentication via API key:
curl https://elizacloud.ai/api/v1/chat/completions \
-H "Authorization: Bearer YOUR_API_KEY" \
-H "Content-Type: application/json" \
-d '{
The task-sending examples show document summaries and data analysis requests being transmitted through the A2A endpoint, and later sections encourage communication with other agents. The documentation does not warn that delegated tasks may expose user-provided content to other agents or external platforms, which is a missing safety disclosure for markdown content.
Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.
For long-running tasks, use streaming:
const response = await fetch("https://elizacloud.ai/api/a2a", {
method: "POST",
headers: {
Authorization: "Bearer YOUR_API_KEY",
The configuration example sets "allowedAgents": ["*"], which models a trust-all policy for inbound or outbound A2A communication. In real deployments, copying this broad allowlist could expose an agent to untrusted peers, expanding attack surface for prompt injection, abusive tasking, data disclosure, or unintended cross-agent actions.
Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.
curl -X POST "https://elizacloud.ai/api/a2a" \
-H "Authorization: Bearer YOUR_API_KEY" \
-H "Content-Type: application/json" \
-d '...'
The chat command sends the user's message to the elizaOS Cloud service via an HTTP POST request, which is a network operation involving user data. While the script logs that it is chatting with an agent, it does not explicitly disclose that the message content will be transmitted to a remote service.
The image generation command submits the user's prompt to the elizaOS Cloud API over the network. The script prints that it is generating an image, but it does not clearly warn users that their prompt text is being sent to an external service.
No suspicious patterns detected.