Back to skill

Security audit

XO Protocol

Security checks for vulnerabilities and agentic risk

Overview

This is a disclosed XO Protocol API/MCP integration for dating trust and profile signals, with sensitive but purpose-aligned network access and example-code cautions.

Install only if you are comfortable giving an AI client access to XO Protocol account-linked trust, reputation, profile, and public-post data through your XO token. Keep XO_API_KEY and XO_ACCESS_TOKEN out of shared config, avoid copying the OAuth examples into production without hardening token isolation and state validation, and disclose to end users when their XO data is fetched or displayed.

Vulnerability Patterns
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (2)

T09 · Insecure Skill Coding Practices

Error
Location
examples/dating-app-integration.js:21
Finding

Shared SDK Client Causes Cross-Session OAuth Token Confusion

Content
View full analysis
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Warning
Location
examples/quickstart.js:117
Finding

Quickstart Demonstrates Ineffective OAuth State Validation

Content
View full analysis
Remediation
View remediation
Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
Findings (16)

Hidden Instructions

High
Category
Prompt Injection
Confidence
70% confidence
Finding

Hidden instructions were detected in comments or invisible text. These could contain malicious directives. Manual review is recommended.

Content

Scanner excerpt · examples/trust-badge.html (reported line 111)May include surrounding context.

html
<div class="demo-grid">

    <!-- Example 1: Verified user with high trust -->
    <div class="xo-trust-badge" id="badge-verified">
      <div class="xo-trust-badge__header">
        <svg viewBox="0 0 24 24" fill="none" stroke="#86868b" stroke-width="2"><path d="M12 22s8-4 8-10V5l-8-3-8 3v7c0 6 8 10 8 10z"/></svg>

Hidden Instructions

High
Category
Prompt Injection
Confidence
70% confidence
Finding

Hidden instructions were detected in comments or invisible text. These could contain malicious directives. Manual review is recommended.

Content

Scanner excerpt · examples/trust-badge.html (reported line 177)May include surrounding context.

html
</div>

  <!-- Integration code example -->
  <div class="code-section">
    <h2>Integration (5 lines)</h2>
    <pre><code><span class="kw">import</span> { <span class="fn">XOClient</span> } <span class="kw">from</span> <span class="str">'@xo-protocol/sdk'</span>

Credential Access

High
Category
Privilege Escalation
Confidence
70% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · README.md (reported line 154)May include surrounding context.

md
}

  /**
   * Set the access token after OAuth flow completes.
   * @param {string} token - JWT access token
   */
  setAccessToken(token) {

Credential Access

High
Category
Privilege Escalation
Confidence
70% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · openapi.yaml (reported line 140)May include surrounding context.

yaml
}

  /**
   * Set the access token after OAuth flow completes.
   * @param {string} token - JWT access token
   */
  setAccessToken(token) {

Credential Access

High
Category
Privilege Escalation
Confidence
70% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · openapi.yaml (reported line 560)May include surrounding context.

yaml
}

  /**
   * Set the access token after OAuth flow completes.
   * @param {string} token - JWT access token
   */
  setAccessToken(token) {

Credential Access

High
Category
Privilege Escalation
Confidence
70% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · sdk/index.js (reported line 32)May include surrounding context.

js
}

  /**
   * Set the access token after OAuth flow completes.
   * @param {string} token - JWT access token
   */
  setAccessToken(token) {

Credential Access

High
Category
Privilege Escalation
Confidence
70% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · sdk/index.js (reported line 33)May include surrounding context.

js
}

  /**
   * Set the access token after OAuth flow completes.
   * @param {string} token - JWT access token
   */
  setAccessToken(token) {

Credential Access

High
Category
Privilege Escalation
Confidence
70% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · sdk/index.js (reported line 78)May include surrounding context.

js
}

  /**
   * Set the access token after OAuth flow completes.
   * @param {string} token - JWT access token
   */
  setAccessToken(token) {

External Transmission

Medium
Category
Data Exfiltration
Confidence
60% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · README.md (reported line 225)May include surrounding context.

1. Direct Authentication (first-party apps)

bash
curl -X POST https://protocol.xoxo.space/protocol/v1/auth/token \
  -H "X-API-Key: your-api-key" \
  -H "Content-Type: application/json" \
  -d '{"grant_type": "firebase", "assertion": "<firebase_id_token>"}'

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
91% confidence
Finding

The skill documents use of environment variables for secrets and outbound network access to a third-party API, but it does not declare any explicit tool scope such as permissions or allowed-tools. This creates a transparency and policy-enforcement gap: an agent platform may permit broader execution than the user expects, and the skill can access sensitive credentials and external endpoints without a clear least-privilege declaration.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
87% confidence
Finding

The code retrieves a full trust profile and stores it in the session, which is handling potentially sensitive user data from a third-party service. While the file comments describe the feature, they do not warn users that detailed profile data will be fetched and stored, and there is no visible confirmation or runtime disclosure near the operation.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
90% confidence
Finding

The MCP server makes authenticated requests using the user's API key and bearer token and exposes personal/social data tools, but the code provides no user-facing disclosure, consent prompt, or usage warning before transmitting or retrieving sensitive account-linked data. In an agent-tooling context, this is risky because users may invoke identity, reputation, profile, or social-signals lookups indirectly through an AI client without clearly understanding that external data sharing is occurring.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

This code file hardcodes placeholders for an API key and OAuth client credentials, then transmits them in token and API requests. Although the header lists prerequisites, it does not warn users about safe secret handling, avoiding hardcoding in real use, or the sensitivity of these values.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The integration example encourages fetching and rendering user-linked identity, reputation, and social-signal data without any visible disclosure, consent flow, or privacy guidance. In a trust/reputation product, this can normalize collecting and exposing sensitive profiling data in downstream apps, creating privacy, compliance, and user-expectation risks.

Content

No source excerpt is available for this finding.

Autonomous Decision Making

Medium
Category
Excessive Agency
Confidence
75% confidence
Finding

Skill enables autonomous high-impact decisions without human-in-the-loop verification. Critical operations (destructive commands, financial transactions, data deletion) should require explicit user confirmation.

Content

Scanner excerpt · openapi.yaml (reported line 8)May include surrounding context.

yaml
The Dating Intelligence API. Identity verification via onchain Soul Bound Tokens,
    AI-powered compatibility scoring, and reputation data through simple REST endpoints.
    All data access requires explicit user authorization — the protocol never exposes
    private information without consent.

    XO Protocol serves as a **social passport for AI agents** — portable identity, trust, and
    compatibility that works across platforms. Credibly neutral, user-authorized.

Vague Triggers

Low
Category
Not specified by scanner
Confidence
84% confidence
Finding

This manifest-style OpenAPI description says the protocol serves as a "social passport for AI agents" but does not define when an agent should invoke the skill versus when it should not. Because this file is a manifest-type file and includes agent-facing positioning without negative examples or bounded activation criteria, it creates ambiguity about trigger scope.

Content

No source excerpt is available for this finding.

Static analysis

Detected: suspicious.env_credential_access

Environment variable access combined with network send.

Critical
Code
suspicious.env_credential_access
Location
examples/mcp-server.js:35