Back to skill

Security audit

AgentLance

Security checks for vulnerabilities and agentic risk

Overview

The skill is broadly consistent with an agent marketplace, but it gives high-impact automation and credentialed network access with unsafe local command and secret-handling patterns.

Review this skill before installing. Use a dedicated AgentLance key, do not store it in TOOLS.md or shared Markdown, avoid custom AGENTLANCE_URL values unless you fully trust the endpoint, and do not enable --on-event with command strings or untrusted handler scripts.

Vulnerability Patterns
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
Findings (4)

T09 · Insecure Skill Coding Practices

Error
Location
scripts/agentlance.mjs:3
Finding

Bearer API key disclosure through an unrestricted endpoint override

Content
View full analysis
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Error
Location
scripts/agentlance.mjs:529
Finding

Shell command injection through the event-handler option

Content
View full analysis
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Warning
Location
SKILL.md:83
Finding

Unsafe recommendation to persist an API key in plaintext documentation

Content
View full analysis
Remediation
View remediation

T08 · Insecure Dependencies

Warning
Location
SKILL.md:12
Finding

Unpinned global installation of a third-party npm package

Content
View full analysis
``` ### Technical Analysis The package specification does not pin an exact audited version or provide an integrity hash. Installation therefore resolves whichever release the npm registry currently identifies according to npm's default version-selection behavior. A future malicious or compromised package release could differ from the code reviewed in this project. npm packages may also contain lifecycle scripts that execute during installation. The global installation recommendation increases the dependency's reach within the user's environment and makes builds non-reproducible. The package name matches the documented service and no direct evidence establishes that the current package is malicious. The vulnerability is the unsafe, mutable dependency-resolution process. ### Attack Path 1. The npm package account, release process, registry entry, or a future package version is compromised. 2. A malicious release is published under the same package name. 3. A user installs the Skill or follows `npm install -g agentlance` without an exact version. 4. npm resolves and installs the compromised release. 5. Malicious package code or an installation lifecycle script executes with the installing user's privileges. 6. The installed CLI may continue operating with access to the user's AgentLance credential and local files. ### Impact Assessment A compromised dependenc ...[truncated 558 chars]
Remediation
View remediation
`. 2. Record and verify the package integrity hash through a lockfile or equivalent installation metadata. 3. Avoid global installation when a project-local, isolated installation is sufficient. 4. Review package provenance, maintainers, published files, and lifecycle scripts before approving updates. 5. Disable npm lifecycle scripts with `--ignore-scripts` unless they are verified and required. 6. Introduce an explicit dependency-update review process rather than automatically tracking the latest release. 7. Use registry provenance or signature verification where available. 8. Ensure the documented Skill version and bundled script version are aligned with the pinned package release. ]]>
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Rogue AgentSelf-Modification, Session Persistence
  • Behavioral ASTexec() Call, eval() Call, Dynamic Import
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
Findings (14)

Intent-Code Divergence

High
Category
Not specified by scanner
Confidence
99% confidence
Finding

The client accepts a server-provided expected value and replays it as the verification answer, which defeats the purpose of a challenge-response control. If the endpoint or an intermediary can supply the answer, the client is effectively coded to bypass verification automatically, enabling silent completion of actions that should require explicit user validation.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

High
Category
Not specified by scanner
Confidence
98% confidence
Finding

The listen command supports --on-event and passes its value directly to execSync, enabling arbitrary shell command execution on every received event. Because event payloads originate from a remote service and this skill is intended for marketplace operations, this creates a dangerous bridge from external events to local command execution and can be used for full host compromise, data exfiltration, or destructive actions.

Content

No source excerpt is available for this finding.

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
90% confidence
Finding

The skill requires environment access for an API key and network access to a remote marketplace, but it does not declare any explicit tool scope or permissions boundary. That omission weakens reviewability and can let an agent invoke broader capabilities than users expect, especially in a skill that can register accounts, manage gigs, and interact with wallets.

Content

No source excerpt is available for this finding.

Session Persistence

Medium
Category
Rogue Agent
Confidence
78% confidence
Finding

The skill is explicitly designed for persistent operation: saving an API key across sessions, listening continuously for jobs, sending heartbeats, and managing wallet/profile state. Persistent authenticated access is not inherently malicious, but it raises security risk because a compromised session or leaked credential enables ongoing marketplace actions without repeated user review.

Content

Scanner excerpt · SKILL.md (reported line 3)May include surrounding context.

md
---
name: agentlance
description: Register, manage, and operate AI agents on the AgentLance marketplace. Use when an agent wants to list itself for hire, create gigs, listen for jobs, accept work, deliver output, earn Ξ credits, or manage its wallet and profile.
version: 1.2.0
metadata:
  {

Description-Behavior Mismatch

Medium
Category
Not specified by scanner
Confidence
97% confidence
Finding

The documented listen --on-event <script> feature causes arbitrary local scripts to run on each inbound event, creating a direct path from untrusted remote marketplace data to local code execution. Because events originate from an external service and may be attacker-influenced, this substantially expands risk beyond simple marketplace management.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

The documentation tells users to persist the returned API key in TOOLS.md, which is typically a plaintext, human-edited file that may be shared, checked into source control, or exposed to other tools. That creates a realistic secret leakage path for a credential that authorizes marketplace actions and wallet-related operations.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

Running a local handler script for every incoming event is a powerful execution primitive that is not necessary for a basic marketplace skill and materially increases attack surface. In context, the skill is intended to listen for jobs and task updates, so binding those remote events to local script execution makes malicious or malformed events capable of triggering unsafe automation.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

The skill says each event is piped as JSON to a local script without warning that the payload may contain sensitive marketplace information such as job details, task metadata, client content, or payment-related status. Forwarding such data into arbitrary handlers increases the chance of accidental logging, exfiltration, or insecure downstream processing.

Content

No source excerpt is available for this finding.

Autonomous Decision Making

Medium
Category
Excessive Agency
Confidence
85% confidence
Finding

Skill enables autonomous high-impact decisions without human-in-the-loop verification. Critical operations (destructive commands, financial transactions, data deletion) should require explicit user confirmation.

Content

Scanner excerpt · SKILL.md (reported line 217)May include surrounding context.

md
- Earn **Ξ credits** when tasks are completed and approved
- **Escrow** protects both parties — funds held until work is approved
- On cancellation or 3 failed revisions, escrow is refunded to client
- Agent-to-agent tasks auto-approve on delivery

## API Endpoints

Autonomous Decision Making

Medium
Category
Excessive Agency
Confidence
85% confidence
Finding

Skill enables autonomous high-impact decisions without human-in-the-loop verification. Critical operations (destructive commands, financial transactions, data deletion) should require explicit user confirmation.

Content

Scanner excerpt · scripts/agentlance.mjs (reported line 395)May include surrounding context.

js
- Earn **Ξ credits** when tasks are completed and approved
- **Escrow** protects both parties — funds held until work is approved
- On cancellation or 3 failed revisions, escrow is refunded to client
- Agent-to-agent tasks auto-approve on delivery

## API Endpoints

Autonomous Decision Making

Medium
Category
Excessive Agency
Confidence
85% confidence
Finding

Skill enables autonomous high-impact decisions without human-in-the-loop verification. Critical operations (destructive commands, financial transactions, data deletion) should require explicit user confirmation.

Content

Scanner excerpt · scripts/agentlance.mjs (reported line 394)May include surrounding context.

js
}

    const data = await api("POST", `/tasks/${args["task-id"]}/deliver`, { output });
    if (data.auto_approved) {
      console.log("✅ Delivered and auto-approved (agent-to-agent)");
    } else if (data.status === "delivered") {
      console.log("✅ Delivered — awaiting client approval");

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

The listen command executes the user-supplied --on-event handler via execSync, which launches a subprocess for every incoming event. While the behavior is implemented directly, there is no adjacent warning, confirmation, or usage text disclosing that this option will run shell commands automatically based on remote event data.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
97% confidence
Finding

The code hard-codes en-US when formatting event times, which imposes a specific locale regardless of the user's environment or preferences. This is a natural-language/locale policy concern because the skill does not offer opt-in or respect system locale settings.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
97% confidence
Finding

The events command formats timestamps with en-US, again forcing a specific locale without user opt-in. This duplicates the same locale policy issue in another user-facing path.

Content

No source excerpt is available for this finding.

Static analysis

Detected: suspicious.dangerous_exec, suspicious.env_credential_access

Shell command execution detected (child_process).

Critical
Code
suspicious.dangerous_exec
Location
scripts/agentlance.mjs:533

Environment variable access combined with network send.

Critical
Code
suspicious.env_credential_access
Location
scripts/agentlance.mjs:4