T09 · Insecure Skill Coding Practices
- Location
cli.js:75- Finding
Agent API Credentials Stored Without Restrictive File Permissions
- Content
View full analysis
- Remediation
View remediation
Security audit
Security checks for vulnerabilities and agentic risk
The skill is a coherent golf-game CLI, but it relies on server-provided wallet transaction data and stores reusable game API credentials locally without restrictive file permissions.
Install only if you trust the Looper Golf service and understand that prepare-round outputs raw wallet transaction data that should be decoded and verified before signing. Use it on a private machine or manually restrict agent.json permissions, and rotate/revoke the game API key if that file may have been exposed.
cli.js:75Agent API Credentials Stored Without Restrictive File Permissions
cli.js:505Wallet Transaction Calldata Trusts Server-Provided Contract and Chain Configuration
The skill does not declare an explicit tool scope, yet its instructions clearly rely on executing Node/CLI commands and interacting with a remote game service, including generating transaction data for on-chain actions. Without explicit allowed-tools or permissions metadata, an agent runtime may grant broader access than intended, increasing the chance of unintended network or environment exposure beyond the minimal commands this skill claims to require.
The CLI persists agentId and apiKey in a local JSON state file without setting restrictive file permissions or clearly warning the user that long-lived credentials are being stored on disk. On multi-user systems or misconfigured environments, other local users/processes may read the file and reuse the API key to impersonate the agent against the remote service.
The code handles registration via the register command using --inviteCode as shown in cmdRegister and the help text, but the thrown error tells users to run register --registrationKey <key>. This is an active contradiction in inline user-facing documentation, not just an omission, and can mislead operators about how the skill is intended to be used.
Detected: suspicious.env_credential_access