Back to skill

Security audit

elizaOS Cloud

Security checks for vulnerabilities and agentic risk

Overview

This elizaOS Cloud skill appears purpose-aligned, but it should be reviewed because it uses a powerful API key for cloud changes and billing-related actions without tight safeguards.

Install only if you trust elizaOS Cloud and will use a narrowly scoped API key. Avoid sending secrets or regulated data in chat, image, knowledge, or A2A payloads; require explicit approval for deletes, billing changes, top-ups, API-key creation, and public/discoverable agent registration. Do not set `ELIZACLOUD_BASE_URL` except to a trusted HTTPS elizaOS endpoint, and prefer a pinned or local CLI install over the optional unpinned global install.

Vulnerability Patterns
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
Findings (2)

T09 · Insecure Skill Coding Practices

Warning
Location
scripts/elizacloud-client.sh:9
Finding

API Key Can Be Transmitted to an Arbitrary Configurable Host

Content
View full analysis
Remediation
View remediation

T08 · Insecure Dependencies

Note
Location
SKILL.md:274
Finding

Optional Installation Uses an Unpinned Global Dependency

Content
View full analysis
Remediation
View remediation
``` 2. Document the expected package registry and verify that scoped packages are resolved only from that registry. 3. Publish and verify integrity checksums or signed release provenance where supported. 4. Prefer a project-local installation over a global installation to reduce scope: ```bash bun add --dev @elizaos/cli@ ``` 5. Avoid running package installation commands with administrator or root privileges. 6. Review lifecycle scripts and package contents before recommending a new version. 7. Use lockfiles for project-local installations and update them only through a controlled dependency-review process. ]]>
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Tool MisuseTool Parameter Abuse, Chaining Abuse, Unsafe Defaults
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
Findings (14)

Tp4

High
Category
MCP Tool Poisoning
Confidence
95% confidence
Finding

The code is clearly related to elizaOS Cloud and accurately uses the declared API key and service domain, so the general service association is correct. However, the declared description materially overstates the implemented functionality. The script only supports status checking, basic agent CRUD, chat completions, and image generation. There is no code for video generation, voice cloning, knowledge base operations, container management, marketplace features, or broader cloud-hosted agent deployment/management workflows. Because the description presents a substantially broader capability set than the code actually provides, this is a description-behavior mismatch.

Content

No source excerpt is available for this finding.

Tool Parameter Abuse

High
Category
Tool Misuse
Confidence
91% confidence
Finding

The documented DELETE endpoint enables destructive actions against cloud-hosted agents and accepts a path parameter that could be driven directly by model-controlled or user-supplied input. In agent environments, this is dangerous because ambiguous prompts, prompt injection, or parameter confusion could trigger irreversible deletion of resources without adequate validation or confirmation.

Content

Scanner excerpt · SKILL.md (reported line 78)May include surrounding context.

Delete Agent

bash
DELETE /api/my-agents/characters/{id}

Image Generation

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
96% confidence
Finding

The skill documents shell-based operations but does not declare any tool scope such as allowed-tools or permissions. That omission weakens execution boundaries and makes it easier for an agent runtime or reviewer to underestimate that the skill can invoke networked shell commands against an external API using sensitive credentials.

Content

No source excerpt is available for this finding.

External Transmission

Medium
Category
Data Exfiltration
Confidence
60% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · SKILL.md (reported line 43)May include surrounding context.

Chat Completions (OpenAI-Compatible)

bash
curl https://elizacloud.ai/api/v1/chat/completions \
  -H "Authorization: Bearer $ELIZACLOUD_API_KEY" \
  -H "Content-Type: application/json" \
  -d '{

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
89% confidence
Finding

The skill includes destructive and cost-incurring operations such as deleting agents, creating API keys, purchasing credits, and enabling auto top-up without prominent warnings or confirmation requirements. In an agent setting, documenting these actions as routine can lead to accidental state changes, financial loss, or service disruption if a model executes them from ambiguous user prompts.

Content

No source excerpt is available for this finding.

External Transmission

Medium
Category
Data Exfiltration
Confidence
60% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · SKILL.md (reported line 220)May include surrounding context.

bash
# 1. Create agent
curl -X POST https://elizacloud.ai/api/v1/app/agents \
  -H "Authorization: Bearer $ELIZACLOUD_API_KEY" \
  -d '{"name": "Support Bot", "bio": "Customer support specialist"}'

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
84% confidence
Finding

This markdown file documents API usage that posts user message content to a remote service, but the surrounding text does not warn readers that prompts and other supplied data will be transmitted off-system. Under the markdown-file criteria for missing user warnings, externally sending user data should be disclosed when privacy or system integrity may be affected.

Content

No source excerpt is available for this finding.

External Transmission

Medium
Category
Data Exfiltration
Confidence
60% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · references/api-reference.md (reported line 302)May include surrounding context.

All API requests require authentication via API key:

bash
curl https://elizacloud.ai/api/v1/chat/completions \
  -H "Authorization: Bearer YOUR_API_KEY" \
  -H "Content-Type: application/json" \
  -d '{

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
88% confidence
Finding

The task-sending examples show document summaries and data analysis requests being transmitted through the A2A endpoint, and later sections encourage communication with other agents. The documentation does not warn that delegated tasks may expose user-provided content to other agents or external platforms, which is a missing safety disclosure for markdown content.

Content

No source excerpt is available for this finding.

External Transmission

Medium
Category
Data Exfiltration
Confidence
60% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · references/api-reference.md (reported line 566)May include surrounding context.

For long-running tasks, use streaming:

javascript
const response = await fetch("https://elizacloud.ai/api/a2a", {
  method: "POST",
  headers: {
    Authorization: "Bearer YOUR_API_KEY",

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
88% confidence
Finding

The configuration example sets "allowedAgents": ["*"], which models a trust-all policy for inbound or outbound A2A communication. In real deployments, copying this broad allowlist could expose an agent to untrusted peers, expanding attack surface for prompt injection, abusive tasking, data disclosure, or unintended cross-agent actions.

Content

No source excerpt is available for this finding.

External Transmission

Medium
Category
Data Exfiltration
Confidence
60% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · references/api-reference.md (reported line 627)May include surrounding context.

API Key

bash
curl -X POST "https://elizacloud.ai/api/a2a" \
  -H "Authorization: Bearer YOUR_API_KEY" \
  -H "Content-Type: application/json" \
  -d '...'

Missing User Warnings

Low
Category
Not specified by scanner
Confidence
91% confidence
Finding

The chat command sends the user's message to the elizaOS Cloud service via an HTTP POST request, which is a network operation involving user data. While the script logs that it is chatting with an agent, it does not explicitly disclose that the message content will be transmitted to a remote service.

Content

No source excerpt is available for this finding.

Missing User Warnings

Low
Category
Not specified by scanner
Confidence
92% confidence
Finding

The image generation command submits the user's prompt to the elizaOS Cloud API over the network. The script prints that it is generating an image, but it does not clearly warn users that their prompt text is being sent to an external service.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.