T09 · Insecure Skill Coding Practices
- Location
examples/dating-app-integration.js:21- Finding
Shared SDK Client Causes Cross-Session OAuth Token Confusion
- Content
View full analysis
- Remediation
View remediation
Security audit
Security checks for vulnerabilities and agentic risk
This is a disclosed XO Protocol API/MCP integration for dating trust and profile signals, with sensitive but purpose-aligned network access and example-code cautions.
Install only if you are comfortable giving an AI client access to XO Protocol account-linked trust, reputation, profile, and public-post data through your XO token. Keep XO_API_KEY and XO_ACCESS_TOKEN out of shared config, avoid copying the OAuth examples into production without hardening token isolation and state validation, and disclose to end users when their XO data is fetched or displayed.
examples/dating-app-integration.js:21Shared SDK Client Causes Cross-Session OAuth Token Confusion
examples/quickstart.js:117Quickstart Demonstrates Ineffective OAuth State Validation
Hidden instructions were detected in comments or invisible text. These could contain malicious directives. Manual review is recommended.
<div class="demo-grid">
<!-- Example 1: Verified user with high trust -->
<div class="xo-trust-badge" id="badge-verified">
<div class="xo-trust-badge__header">
<svg viewBox="0 0 24 24" fill="none" stroke="#86868b" stroke-width="2"><path d="M12 22s8-4 8-10V5l-8-3-8 3v7c0 6 8 10 8 10z"/></svg>
Hidden instructions were detected in comments or invisible text. These could contain malicious directives. Manual review is recommended.
</div>
<!-- Integration code example -->
<div class="code-section">
<h2>Integration (5 lines)</h2>
<pre><code><span class="kw">import</span> { <span class="fn">XOClient</span> } <span class="kw">from</span> <span class="str">'@xo-protocol/sdk'</span>
Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.
}
/**
* Set the access token after OAuth flow completes.
* @param {string} token - JWT access token
*/
setAccessToken(token) {
Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.
}
/**
* Set the access token after OAuth flow completes.
* @param {string} token - JWT access token
*/
setAccessToken(token) {
Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.
}
/**
* Set the access token after OAuth flow completes.
* @param {string} token - JWT access token
*/
setAccessToken(token) {
Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.
}
/**
* Set the access token after OAuth flow completes.
* @param {string} token - JWT access token
*/
setAccessToken(token) {
Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.
}
/**
* Set the access token after OAuth flow completes.
* @param {string} token - JWT access token
*/
setAccessToken(token) {
Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.
}
/**
* Set the access token after OAuth flow completes.
* @param {string} token - JWT access token
*/
setAccessToken(token) {
Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.
curl -X POST https://protocol.xoxo.space/protocol/v1/auth/token \
-H "X-API-Key: your-api-key" \
-H "Content-Type: application/json" \
-d '{"grant_type": "firebase", "assertion": "<firebase_id_token>"}'
The skill documents use of environment variables for secrets and outbound network access to a third-party API, but it does not declare any explicit tool scope such as permissions or allowed-tools. This creates a transparency and policy-enforcement gap: an agent platform may permit broader execution than the user expects, and the skill can access sensitive credentials and external endpoints without a clear least-privilege declaration.
The code retrieves a full trust profile and stores it in the session, which is handling potentially sensitive user data from a third-party service. While the file comments describe the feature, they do not warn users that detailed profile data will be fetched and stored, and there is no visible confirmation or runtime disclosure near the operation.
The MCP server makes authenticated requests using the user's API key and bearer token and exposes personal/social data tools, but the code provides no user-facing disclosure, consent prompt, or usage warning before transmitting or retrieving sensitive account-linked data. In an agent-tooling context, this is risky because users may invoke identity, reputation, profile, or social-signals lookups indirectly through an AI client without clearly understanding that external data sharing is occurring.
This code file hardcodes placeholders for an API key and OAuth client credentials, then transmits them in token and API requests. Although the header lists prerequisites, it does not warn users about safe secret handling, avoiding hardcoding in real use, or the sensitivity of these values.
The integration example encourages fetching and rendering user-linked identity, reputation, and social-signal data without any visible disclosure, consent flow, or privacy guidance. In a trust/reputation product, this can normalize collecting and exposing sensitive profiling data in downstream apps, creating privacy, compliance, and user-expectation risks.
Skill enables autonomous high-impact decisions without human-in-the-loop verification. Critical operations (destructive commands, financial transactions, data deletion) should require explicit user confirmation.
The Dating Intelligence API. Identity verification via onchain Soul Bound Tokens,
AI-powered compatibility scoring, and reputation data through simple REST endpoints.
All data access requires explicit user authorization — the protocol never exposes
private information without consent.
XO Protocol serves as a **social passport for AI agents** — portable identity, trust, and
compatibility that works across platforms. Credibly neutral, user-authorized.
This manifest-style OpenAPI description says the protocol serves as a "social passport for AI agents" but does not define when an agent should invoke the skill versus when it should not. Because this file is a manifest-type file and includes agent-facing positioning without negative examples or bounded activation criteria, it creates ambiguity about trigger scope.
Detected: suspicious.env_credential_access