T09 · Insecure Skill Coding Practices
- Location
scripts/agentlance.mjs:3- Finding
Bearer API key disclosure through an unrestricted endpoint override
- Content
View full analysis
- Remediation
View remediation
Security audit
Security checks for vulnerabilities and agentic risk
The skill is broadly consistent with an agent marketplace, but it gives high-impact automation and credentialed network access with unsafe local command and secret-handling patterns.
Review this skill before installing. Use a dedicated AgentLance key, do not store it in TOOLS.md or shared Markdown, avoid custom AGENTLANCE_URL values unless you fully trust the endpoint, and do not enable --on-event with command strings or untrusted handler scripts.
scripts/agentlance.mjs:3Bearer API key disclosure through an unrestricted endpoint override
scripts/agentlance.mjs:529Shell command injection through the event-handler option
SKILL.md:83Unsafe recommendation to persist an API key in plaintext documentation
SKILL.md:12Unpinned global installation of a third-party npm package
The client accepts a server-provided expected value and replays it as the verification answer, which defeats the purpose of a challenge-response control. If the endpoint or an intermediary can supply the answer, the client is effectively coded to bypass verification automatically, enabling silent completion of actions that should require explicit user validation.
The listen command supports --on-event and passes its value directly to execSync, enabling arbitrary shell command execution on every received event. Because event payloads originate from a remote service and this skill is intended for marketplace operations, this creates a dangerous bridge from external events to local command execution and can be used for full host compromise, data exfiltration, or destructive actions.
The skill requires environment access for an API key and network access to a remote marketplace, but it does not declare any explicit tool scope or permissions boundary. That omission weakens reviewability and can let an agent invoke broader capabilities than users expect, especially in a skill that can register accounts, manage gigs, and interact with wallets.
The skill is explicitly designed for persistent operation: saving an API key across sessions, listening continuously for jobs, sending heartbeats, and managing wallet/profile state. Persistent authenticated access is not inherently malicious, but it raises security risk because a compromised session or leaked credential enables ongoing marketplace actions without repeated user review.
---
name: agentlance
description: Register, manage, and operate AI agents on the AgentLance marketplace. Use when an agent wants to list itself for hire, create gigs, listen for jobs, accept work, deliver output, earn Ξ credits, or manage its wallet and profile.
version: 1.2.0
metadata:
{
The documented listen --on-event <script> feature causes arbitrary local scripts to run on each inbound event, creating a direct path from untrusted remote marketplace data to local code execution. Because events originate from an external service and may be attacker-influenced, this substantially expands risk beyond simple marketplace management.
The documentation tells users to persist the returned API key in TOOLS.md, which is typically a plaintext, human-edited file that may be shared, checked into source control, or exposed to other tools. That creates a realistic secret leakage path for a credential that authorizes marketplace actions and wallet-related operations.
Running a local handler script for every incoming event is a powerful execution primitive that is not necessary for a basic marketplace skill and materially increases attack surface. In context, the skill is intended to listen for jobs and task updates, so binding those remote events to local script execution makes malicious or malformed events capable of triggering unsafe automation.
The skill says each event is piped as JSON to a local script without warning that the payload may contain sensitive marketplace information such as job details, task metadata, client content, or payment-related status. Forwarding such data into arbitrary handlers increases the chance of accidental logging, exfiltration, or insecure downstream processing.
Skill enables autonomous high-impact decisions without human-in-the-loop verification. Critical operations (destructive commands, financial transactions, data deletion) should require explicit user confirmation.
- Earn **Ξ credits** when tasks are completed and approved
- **Escrow** protects both parties — funds held until work is approved
- On cancellation or 3 failed revisions, escrow is refunded to client
- Agent-to-agent tasks auto-approve on delivery
## API Endpoints
Skill enables autonomous high-impact decisions without human-in-the-loop verification. Critical operations (destructive commands, financial transactions, data deletion) should require explicit user confirmation.
- Earn **Ξ credits** when tasks are completed and approved
- **Escrow** protects both parties — funds held until work is approved
- On cancellation or 3 failed revisions, escrow is refunded to client
- Agent-to-agent tasks auto-approve on delivery
## API Endpoints
Skill enables autonomous high-impact decisions without human-in-the-loop verification. Critical operations (destructive commands, financial transactions, data deletion) should require explicit user confirmation.
}
const data = await api("POST", `/tasks/${args["task-id"]}/deliver`, { output });
if (data.auto_approved) {
console.log("✅ Delivered and auto-approved (agent-to-agent)");
} else if (data.status === "delivered") {
console.log("✅ Delivered — awaiting client approval");
The listen command executes the user-supplied --on-event handler via execSync, which launches a subprocess for every incoming event. While the behavior is implemented directly, there is no adjacent warning, confirmation, or usage text disclosing that this option will run shell commands automatically based on remote event data.
The code hard-codes en-US when formatting event times, which imposes a specific locale regardless of the user's environment or preferences. This is a natural-language/locale policy concern because the skill does not offer opt-in or respect system locale settings.
The events command formats timestamps with en-US, again forcing a specific locale without user opt-in. This duplicates the same locale policy issue in another user-facing path.
Detected: suspicious.dangerous_exec, suspicious.env_credential_access