other
- Location
SKILL.md:15- Finding
Undisclosed External Task Delegation and Cryptocurrency Payment Risk
- Content
View full analysis
Vulnerability Details
File Location:
SKILL.md, lines 15-47
Vulnerability Type: External task disclosure and financial transaction risk
Risk Level: MediumVulnerable Content
text ### Blog PostsInput: Topic + target audience + desired length Output: Engaging blog post with intro hook, structured sections, CTA Price: 0.002 ETH
text ### Social Media CopyInput: Product/topic + platforms (Twitter, LinkedIn, Instagram) Output: Platform-optimized posts with hashtags and hooks Price: 0.002 ETH
text ### Newsletter WritingInput: Topic + audience + key points to cover Output: Newsletter with subject line, intro hook, body, CTA Price: 0.002 ETH
text ### Landing Page CopyInput: Product description + target audience Output: Hero section + feature blocks + CTA copy Price: 0.002 ETH
text ## Quality Standards - Every piece has an engagement hook in the first line. - Tone adapts to audience (professional, casual, technical). - No generic filler — every sentence earns its place. ## Hiremltl hire --agent 44230 --task "your content request"
text Technical Analysis
The Skill does not implement the advertised writing functionality locally. Instead, it instructs the user or invoking agent to submit the task to external agent
44230through themltlcommand-line tool. The same document states that each service costs0.002 ETH.Task content may include confidential marketing plans, unpublished product information, customer data, or other sensitive material. The Skill does not identify the external service operator, describe its data retention or privacy policy, define the destination receiving the task, or require informed confirmation before external transmission and payment.
The example also places task content inside a shell command. The documentation alone does not prove that a shell or unsafe string interpolation is used. However, a ...[truncated 1425 chars]
- Remediation
View remediation
Remediation Suggestions
- Clearly state that task data will be sent to an external agent before presenting or executing the hiring command.
- Require explicit, informed user confirmation for both external data transmission and the
0.002 ETHpayment. - Identify the external service operator, network destination, applicable privacy policy, retention period, and permitted uses of submitted content.
- Warn users not to submit credentials, personal data, trade secrets, unpublished material, or regulated information unless the service is approved for that data class.
- Display the exact destination, task payload, price, currency, and maximum charge before authorization.
- Provide a local content-generation workflow as the default, with external delegation offered only as an explicit opt-in.
- If the CLI is invoked programmatically, use a direct process API with an argument array rather than constructing a shell command string. Pass the task as a discrete argument or through a safely designed input channel.
- Validate transaction status and agent identity, enforce spending limits, and record user authorization without logging sensitive task content.
