Back to skill

Security audit

Claude Api Anthropic

Security checks for vulnerabilities and agentic risk

Overview

This is mostly a documentation skill for Claude APIs, but some copyable agent examples use high-impact permissions, mutable MCP package execution, and database credentials without enough safety scoping.

Review this skill before installing if you expect it to generate production integration code. Pin MCP package versions, avoid npx @latest, use least-privilege database credentials, prefer default or plan permission modes, and redact sensitive prompts, files, tool results, and conversation history before sending them to external APIs.

Vulnerability Patterns
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (1)

T08 · Insecure Dependencies

Warning
Location
python/agent-sdk/patterns.md:162
Finding

Unpinned MCP Packages Are Downloaded and Executed Through npx

Content
View full analysis

Vulnerability Details

File Locations:

  • python/agent-sdk/README.md:132
  • python/agent-sdk/patterns.md:139
  • python/agent-sdk/patterns.md:162-164
  • typescript/agent-sdk/README.md:78
  • typescript/agent-sdk/patterns.md:93

Vulnerability Type: Runtime execution of mutable, unpinned third-party dependencies
Risk Level: Medium

Vulnerable Code

python/agent-sdk/README.md:132:

python
"playwright": {"command": "npx", "args": ["@playwright/mcp@latest"]}

python/agent-sdk/patterns.md:139:

python
"playwright": {"command": "npx", "args": ["@playwright/mcp@latest"]}

python/agent-sdk/patterns.md:162-164:

python
"command": "npx",
"args": ["-y", "@modelcontextprotocol/server-postgres"],
"env": {"DATABASE_URL": os.environ["DATABASE_URL"]}

typescript/agent-sdk/README.md:78:

typescript
playwright: { command: "npx", args: ["@playwright/mcp@latest"] },

typescript/agent-sdk/patterns.md:93:

typescript
playwright: { command: "npx", args: ["@playwright/mcp@latest"] },

Technical Analysis

The examples instruct users to start MCP servers through npx. If the requested package is not already installed, npx retrieves it from the package registry and executes it locally.

The Playwright examples explicitly use the mutable @latest tag. The PostgreSQL example omits a version entirely and uses -y, suppressing interactive confirmation. Consequently, the code executed when a user follows these examples is not fixed to the package contents reviewed with this Skill.

This creates a supply-chain trust boundary: a compromised registry account, malicious package release, or compromised upstream maintainer could replace the effective runtime payload without requiring any modification to the Skill. The PostgreSQL MCP process is particularly sensitive because it is explicitly given DATABASE_URL, which may contain a database hostname, usernam ...[truncated 2250 chars]

Remediation
View remediation

Remediation Suggestions

  1. Replace mutable and unversioned dependencies with exact, reviewed versions:

    python
    "playwright": {
        "command": "npx",
        "args": ["--no-install", "@playwright/mcp@X.Y.Z"]
    }
    
    python
    "postgres": {
        "command": "npx",
        "args": ["--no-install", "@modelcontextprotocol/server-postgres@X.Y.Z"],
        "env": {"DATABASE_URL": os.environ["DATABASE_URL"]}
    }
    
  2. Install MCP packages as project dependencies before execution and commit the applicable lockfile. Use locked, integrity-verified installation commands such as npm ci.

  3. Prefer invoking a package from the project's verified local dependency tree rather than allowing npx to download missing code at runtime.

  4. Remove @latest, add exact versions to all examples, and avoid npx -y where confirmation provides a meaningful security boundary.

  5. Document that MCP servers are locally executed third-party programs rather than passive API definitions.

  6. Run MCP servers in a restricted environment with:

    • A dedicated operating-system account or container.
    • Access only to the necessary working directory.
    • Restricted outbound network access.
    • A minimal environment-variable allowlist.
    • Resource and execution-time limits.
  7. For PostgreSQL integration, use a dedicated database account limited to the required database, schema, tables, and operations. Prefer read-only credentials for analytical queries and rotate the credential if package compromise is suspected.

  8. Review package provenance, release signatures, maintainers, and published integrity metadata before updating pinned versions. Test updates in an isolated environment before deployment.

Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Memory PoisoningPersistent Context Injection, Context Window Stuffing, Memory Manipulation
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
Findings (37)

Context Leakage

High
Category
Data Exfiltration
Confidence
95% confidence
Finding

The instruction to send the full conversation history each time encourages broad context retransmission, which can leak prior sensitive content far beyond what is needed for the current turn. In an API integration guide, this is especially risky because developers may implement it verbatim, causing persistent disclosure of secrets, credentials, personal data, or internal business context to the external model provider.

Content

Scanner excerpt · python/claude-api/README.md (reported line 213)May include surrounding context.

Multi-Turn Conversations

The API is stateless — send the full conversation history each time.

python
class ConversationManager:

Context Leakage

High
Category
Data Exfiltration
Confidence
75% confidence
Finding

Code or instructions that leak agent conversation context to external services, potentially exposing sensitive user interactions.

Content

Scanner excerpt · shared/live-sources.md (reported line 63)May include surrounding context.

md
| Structured Outputs | `https://platform.claude.com/docs/en/build-with-claude/structured-outputs.md` | "Extract output_config.format usage and schema enforcement"                           |
| Compaction         | `https://platform.claude.com/docs/en/build-with-claude/compaction.md`         | "Extract compaction setup, trigger config, and streaming with compaction"             |
| Citations          | `https://platform.claude.com/docs/en/build-with-claude/citations.md`          | "Extract citation format and implementation"        |
| Context Windows    | `https://platform.claude.com/docs/en/build-with-claude/context-windows.md`    | "Extract context window sizes and token management" |

---

Context Leakage

High
Category
Data Exfiltration
Confidence
85% confidence
Finding

Code or instructions that leak agent conversation context to external services, potentially exposing sensitive user interactions.

Content

Scanner excerpt · typescript/claude-api/README.md (reported line 207)May include surrounding context.

Multi-Turn Conversations

The API is stateless — send the full conversation history each time. Use Anthropic.MessageParam[] to type the messages array:

typescript
const messages: Anthropic.MessageParam[] = [

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

The skill explicitly instructs the agent to ALWAYS use a specific premium model unless the user names another one. This overrides normal user-choice and cost/fit considerations, and can steer downstream behavior toward unnecessary spend or unsuitable defaults without informed opt-in.

Content

No source excerpt is available for this finding.

Context Window Stuffing

Medium
Category
Memory Poisoning
Confidence
80% confidence
Finding

Skill attempts to fill the context window with filler content, displacing legitimate instructions and safety constraints. This can degrade agent performance or bypass safety boundaries.

Content

Scanner excerpt · SKILL.md (reported line 183)May include surrounding context.

md
**Chat UI or real-time response display:**
→ Read `{lang}/claude-api/README.md` + `{lang}/claude-api/streaming.md`

**Long-running conversations (may exceed context window):**
→ Read `{lang}/claude-api/README.md` — see Compaction section

**Function calling / tool use / agents:**

External Transmission

Medium
Category
Data Exfiltration
Confidence
60% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · curl/examples.md (reported line 1)May include surrounding context.

md
# Claude API — cURL / Raw HTTP

Use these examples when the user needs raw HTTP requests or is working in a language without an official SDK.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The examples instruct users to send prompts, conversation content, and tool results to Anthropic's external API but do not warn that this transmits potentially sensitive data off-host. In the tool-use example, the guidance explicitly says to send tool results back, which can amplify accidental disclosure if those results contain secrets, internal records, or personal data.

Content

No source excerpt is available for this finding.

External Transmission

Medium
Category
Data Exfiltration
Confidence
50% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · curl/examples.md (reported line 16)May include surrounding context.

Basic Message Request

bash
curl https://api.anthropic.com/v1/messages \
  -H "Content-Type: application/json" \
  -H "x-api-key: $ANTHROPIC_API_KEY" \
  -H "anthropic-version: 2023-06-01" \

External Transmission

Medium
Category
Data Exfiltration
Confidence
50% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · curl/examples.md (reported line 34)May include surrounding context.

Basic Message Request

bash
curl https://api.anthropic.com/v1/messages \
  -H "Content-Type: application/json" \
  -H "x-api-key: $ANTHROPIC_API_KEY" \
  -H "anthropic-version: 2023-06-01" \

External Transmission

Medium
Category
Data Exfiltration
Confidence
50% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · curl/examples.md (reported line 73)May include surrounding context.

Basic Message Request

bash
curl https://api.anthropic.com/v1/messages \
  -H "Content-Type: application/json" \
  -H "x-api-key: $ANTHROPIC_API_KEY" \
  -H "anthropic-version: 2023-06-01" \

External Transmission

Medium
Category
Data Exfiltration
Confidence
50% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · curl/examples.md (reported line 98)May include surrounding context.

Basic Message Request

bash
curl https://api.anthropic.com/v1/messages \
  -H "Content-Type: application/json" \
  -H "x-api-key: $ANTHROPIC_API_KEY" \
  -H "anthropic-version: 2023-06-01" \

External Transmission

Medium
Category
Data Exfiltration
Confidence
50% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · curl/examples.md (reported line 138)May include surrounding context.

Basic Message Request

bash
curl https://api.anthropic.com/v1/messages \
  -H "Content-Type: application/json" \
  -H "x-api-key: $ANTHROPIC_API_KEY" \
  -H "anthropic-version: 2023-06-01" \

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
90% confidence
Finding

The README explicitly demonstrates permission_mode="acceptEdits" and documents dontAsk/bypassPermissions, which lowers safety barriers for file modification in agent-driven workflows. In an agent SDK context, normalizing unattended edits without an adjacent warning about code tampering, accidental changes, or the need for tight tool/cwd scoping can lead developers to deploy unsafe defaults that enable destructive or unauthorized repository changes.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
82% confidence
Finding

This markdown example shows passing DATABASE_URL from the environment into an MCP server, which involves sensitive credential handling and potential database access, but the surrounding description does not warn users about using production credentials or exposing sensitive connection data. Under the markdown-file criteria, behaviors affecting privacy or system integrity should include warnings.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

The README demonstrates sending user text and images to a third-party API but provides no privacy or data-sharing warning. In a documentation skill, this can lead developers to transmit sensitive personal, proprietary, or regulated data without realizing it leaves their environment and may be retained or processed externally.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The conversation examples explicitly instruct developers to resend full conversation history on every call without warning that prior user messages may contain sensitive data. This increases the chance of unnecessary over-sharing, larger exposure scope per request, and accidental transmission of historic secrets or personal information.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
89% confidence
Finding

This markdown file documents use of a remote batch API and shows user-provided content being submitted asynchronously, but it does not warn that prompts or documents are transmitted to an external service and that results remain available for 29 days. For markdown files, omission of warnings about behaviors affecting user data or privacy is in scope for missing user warnings.

Content

No source excerpt is available for this finding.

Autonomous Decision Making

Medium
Category
Excessive Agency
Confidence
80% confidence
Finding

Skill enables autonomous high-impact decisions without human-in-the-loop verification. Critical operations (destructive commands, financial transactions, data deletion) should require explicit user confirmation.

Content

Scanner excerpt · go/claude-api.md (reported line 113)May include surrounding context.

md
# Your implementation here
    return f"72°F and sunny in {location}"

# The tool runner handles the agentic loop automatically
runner = client.beta.messages.tool_runner(
    model="claude-opus-4-6",
    max_tokens=4096,

Autonomous Decision Making

Medium
Category
Excessive Agency
Confidence
80% confidence
Finding

Skill enables autonomous high-impact decisions without human-in-the-loop verification. Critical operations (destructive commands, financial transactions, data deletion) should require explicit user confirmation.

Content

Scanner excerpt · python/claude-api/tool-use.md (reported line 28)May include surrounding context.

md
# Your implementation here
    return f"72°F and sunny in {location}"

# The tool runner handles the agentic loop automatically
runner = client.beta.messages.tool_runner(
    model="claude-opus-4-6",
    max_tokens=4096,

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

The Memory Tool examples demonstrate storing user preferences and 'remember' behavior without any accompanying notice about persistence, retention scope, or consent. In an SDK/documentation context, developers may copy this pattern directly into applications and unintentionally build silent preference retention, creating privacy and compliance risk around collection and storage of personal data.

Content

No source excerpt is available for this finding.

Whitespace Padding

Medium
Category
Prompt Injection
Confidence
70% confidence
Finding

Large whitespace padding was detected (a block of blank lines or a long run of spaces). This can push injected instructions below or to the right of the visible area so a human reviewer never sees them while the agent still reads them. Manual review of the hidden content is recommended.

Content

Scanner excerpt · shared/live-sources.md (reported line 41)May include surrounding context.

md
### API Operations

| Topic            | URL                                                                         | Extraction Prompt                                                                                       |
| ---------------- | --------------------------------------------------------------------------- | ------------------------------------------------------------------------------------------------------- |
| Batch Processing | `https://platform.claude.com/docs/en/build-with-claude/batch-processing.md` | "Extract batch API endpoints, request format, and polling for results"                                  |
| Files API        | `https://platform.claude.com/docs/en/build-with-claude/files.md`            | "Extract file upload, download, and referencing in messages, including supported types and beta header" |

Whitespace Padding

Medium
Category
Prompt Injection
Confidence
70% confidence
Finding

Large whitespace padding was detected (a block of blank lines or a long run of spaces). This can push injected instructions below or to the right of the visible area so a human reviewer never sees them while the agent still reads them. Manual review of the hidden content is recommended.

Content

Scanner excerpt · shared/live-sources.md (reported line 93)May include surrounding context.

md
### API Operations

| Topic            | URL                                                                         | Extraction Prompt                                                                                       |
| ---------------- | --------------------------------------------------------------------------- | ------------------------------------------------------------------------------------------------------- |
| Batch Processing | `https://platform.claude.com/docs/en/build-with-claude/batch-processing.md` | "Extract batch API endpoints, request format, and polling for results"                                  |
| Files API        | `https://platform.claude.com/docs/en/build-with-claude/files.md`            | "Extract file upload, download, and referencing in messages, including supported types and beta header" |

Whitespace Padding

Medium
Category
Prompt Injection
Confidence
70% confidence
Finding

Large whitespace padding was detected (a block of blank lines or a long run of spaces). This can push injected instructions below or to the right of the visible area so a human reviewer never sees them while the agent still reads them. Manual review of the hidden content is recommended.

Content

Scanner excerpt · shared/live-sources.md (reported line 51)May include surrounding context.

md
### Tools

| Topic          | URL                                                                                    | Extraction Prompt                                                                        |
| -------------- | -------------------------------------------------------------------------------------- | ---------------------------------------------------------------------------------------- |
| Code Execution | `https://platform.claude.com/docs/en/agents-and-tools/tool-use/code-execution-tool.md` | "Extract code execution tool setup, file upload, container reuse, and response handling" |
| Computer Use   | `https://platform.claude.com/docs/en/agents-and-tools/tool-use/computer-use.md`        | "Extract computer use tool setup, capabilities, and implementation examples"             |

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
87% confidence
Finding

The README lists WebSearch and WebFetch as built-in tools without explaining that using them may send prompts, URLs, or derived context to external services and retrieve untrusted remote content. For an agent SDK, this can mislead adopters into enabling networked capabilities without considering privacy, compliance, or data handling requirements.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

The README explicitly documents permissionMode: "acceptEdits" as a normal usage pattern without a nearby warning that it allows automatic modification of user files. In an agent SDK, normalizing auto-accepted edits can lead integrators to deploy agents that change source code or config without meaningful review, increasing the chance of destructive or unsafe changes.

Content

No source excerpt is available for this finding.

Static analysis

Detected: suspicious.exposed_secret_literal, suspicious.prompt_injection_instructions

File appears to expose a hardcoded API secret or token.

Critical
Code
suspicious.exposed_secret_literal
Location
csharp/claude-api.md:21

Prompt-injection style instruction pattern detected.

Warn
Code
suspicious.prompt_injection_instructions
Location
typescript/agent-sdk/patterns.md:140