Back to skill

Security audit

Verfi

Security checks for vulnerabilities and agentic risk

Overview

The skill is a coherent Verfi consent-verification integration, but it needs Review because it enables broad form-activity recording and secret-key powered tooling without enough scoping, consent, or supply-chain controls.

Install only after reviewing Verfi's privacy, consent, retention, and tenant-access controls. Use explicit user notice and legally appropriate consent before session recording, limit SDK deployment to required forms, use CSP or integrity/version controls where possible, and provide narrowly scoped, rotatable secret keys. Avoid the unpinned npx MCP configuration in production unless you pin and verify the package and run it in a restricted environment.

Vulnerability Patterns
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (2)

T08 · Insecure Dependencies

Error
Location
SKILL.md:116
Finding

Unpinned MCP Package Is Downloaded and Executed with a Secret API Key

Content
View full analysis
Remediation
View remediation

T03 · Remote Payload Retrieval and Execution

Error
Location
SKILL.md:23
Finding

Mutable Remote SDK Executes with Full Page-Origin Access

Content
View full analysis
``` ### Technical Analysis The Skill instructs publishers to load JavaScript directly from `https://sdk.verfi.io/v1/verfi.js`. The URL identifies a version family rather than an immutable, content-addressed artifact, and the script tag does not include a Subresource Integrity (`integrity`) value. Consequently, the JavaScript executed by a publisher's visitors can change after the Skill or website integration has been reviewed. A remotely modified script executes in the security context of the embedding page and is not limited by the public Verfi API key. It can interact with the page DOM, read form values, observe browser events, modify submissions, and access browser-side data available to ordinary same-page scripts. This exposure is especially sensitive because the documented purpose of the SDK is to detect forms and observe mouse movements, clicks, scrolling, keystrokes, form interactions, consent state, device attributes, and PII fields. Although the documentation states that keystroke content is not recorded and PII is hashed, those guarantees cannot be independently enforced by the static script tag if the remote payload changes. This finding does not establish that the current hosted SDK is malicious. Exploitation requires compromise or unauthorized modification of the SDK hosting, publication pipeline, DNS/TLS path, or an authorized but unsafe remote release. ### Attack Path 1. An attacker compromises the SDK hosting environment, deployment credentials, release pipeline, or another component capable of modifying `https://sdk.verfi.io/v1/verfi.js`. 2. The attacker replaces o ...[truncated 1337 chars]
Remediation
View remediation
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (9)

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The skill explicitly states that the SDK auto-records mouse movements, clicks, keystrokes, and scroll activity, but it does not pair that capability with a clear, prominent warning about the privacy implications or limits on capture. In a lead-generation context, this can result in covert collection of sensitive behavioral and form data, creating significant privacy, compliance, and consent risk if deployed without explicit notice and appropriate controls.

Content

No source excerpt is available for this finding.

External Transmission

Medium
Category
Data Exfiltration
Confidence
50% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · SKILL.md (reported line 34)May include surrounding context.

md
# Verfi API Reference

Base URL: `https://api.verfi.io/tenant/v1`

All requests require: `Authorization: Bearer sk_YOUR_SECRET_KEY`

External Transmission

Medium
Category
Data Exfiltration
Confidence
50% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · SKILL.md (reported line 43)May include surrounding context.

md
# Verfi API Reference

Base URL: `https://api.verfi.io/tenant/v1`

All requests require: `Authorization: Bearer sk_YOUR_SECRET_KEY`

External Transmission

Medium
Category
Data Exfiltration
Confidence
50% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · SKILL.md (reported line 63)May include surrounding context.

md
# Verfi API Reference

Base URL: `https://api.verfi.io/tenant/v1`

All requests require: `Authorization: Bearer sk_YOUR_SECRET_KEY`

External Transmission

Medium
Category
Data Exfiltration
Confidence
50% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · SKILL.md (reported line 130)May include surrounding context.

md
# Verfi API Reference

Base URL: `https://api.verfi.io/tenant/v1`

All requests require: `Authorization: Bearer sk_YOUR_SECRET_KEY`

External Transmission

Medium
Category
Data Exfiltration
Confidence
50% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · references/api-reference.md (reported line 3)May include surrounding context.

md
# Verfi API Reference

Base URL: `https://api.verfi.io/tenant/v1`

All requests require: `Authorization: Bearer sk_YOUR_SECRET_KEY`

Context-Inappropriate Capability

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The API explicitly documents cross-tenant session lookup, allowing any tenant with the appropriate scope to search any session by Verfi ID or proof URL. In a consent-verification product, this exceeds least-privilege expectations and creates an authorization/privacy risk because tenant boundaries are intentionally bypassed for records that may reveal consent status and related metadata.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

The documented lookup and proof endpoints expose privacy-sensitive data across tenant boundaries, including hashed identifiers, consent verification results, interaction telemetry, device attributes, and proof URLs. Even when some PII is hashed, these data elements can enable correlation, reidentification, targeted abuse, or unauthorized inspection of user consent records, especially when accessible cross-tenant and without prominent privacy/security constraints.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

The documentation describes an SDK that automatically records extensive behavioral telemetry across forms, including mouse movements, clicks, scrolls, typing patterns, consent interactions, device metadata, and hashed PII, but it does not clearly warn implementers to obtain informed user consent or provide prominent notice before collection. In a lead-generation/TCPA compliance context, this is risky because developers may deploy the SDK exactly as documented, resulting in privacy-invasive monitoring and potential regulatory or consent failures despite the product's compliance-oriented purpose.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.