Back to skill

Security audit

rtc-work

Security checks for vulnerabilities and agentic risk

Overview

The skill appears purpose-aligned, but it tells users to run an unpinned remote CLI for wallet-adjacent job-market actions, so it should be reviewed before installation.

Install only from a reviewed, pinned version such as the inspected 0.1.1 release, avoid running unpinned `uvx rtc-work` in sensitive environments, and use `--yes` or `watch --auto` only when you are comfortable with automatic job-market state changes.

Vulnerability Patterns
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
Findings (2)

T08 · Insecure Dependencies

Warning
Location
SKILL.md:7
Finding

Unpinned Remote Package Resolution and Execution

Content
View full analysis

Vulnerability Details

File Location: SKILL.md:7-12, README.md:7-13, and pyproject.toml:1-3
Vulnerability Type: Software supply-chain risk caused by unpinned remote packages
Risk Level: Medium

Vulnerable Code

SKILL.md:7-12:

bash
## Use
text
uvx rtc-work jobs                          # list open jobs
uvx rtc-work watch --skills code,research  # poll for matches
uvx rtc-work claim <job_id>                # reserve a job
uvx rtc-work deliver <job_id> --summary "done"

README.md:7-13:

bash
uvx rtc-work jobs                         # list open jobs
uvx rtc-work watch --skills code,research # poll for matches (report-only)
uvx rtc-work claim  <job_id>              # reserve a job
uvx rtc-work deliver <job_id> --url https://… --summary "done"
uvx rtc-work rep                          # your on-chain reputation

pyproject.toml:1-3:

toml
[build-system]
requires = ["setuptools>=61"]
build-backend = "setuptools.build_meta"

Technical Analysis

The documented uvx rtc-work commands resolve and execute a package from the configured Python package index without specifying an exact version or verifying a package hash. This means that the code executed by users can differ from the source reviewed in this audit.

The build-system dependency also specifies only a minimum version of setuptools, with no upper bound, lock file, or integrity hash. During an isolated build, a later compatible release may therefore be downloaded and executed as part of the build process.

This is not evidence that the currently reviewed package contains malicious code. It is a supply-chain weakness: trust is transferred to future package releases, package-index accounts, index configuration, and dependency resolution performed at execution or build time.

Attack Path

  1. An attacker compromises the publishing account for rtc-work, com ...[truncated 1118 chars]
Remediation
View remediation

Remediation Suggestions

  • Pin the application version in all execution examples, such as uvx rtc-work==0.1.1 ....
  • Prefer installation or execution from a reviewed, versioned release artifact rather than an implicitly selected latest release.
  • Publish and verify cryptographic hashes or signed provenance for release artifacts.
  • Pin build dependencies to reviewed versions and maintain them through a controlled update process.
  • Use a lock file or constraints file with hashes in reproducible build and release workflows.
  • Configure CI to build in a restricted environment and verify that resolved package versions match the approved dependency set.
  • Document the expected package index and warn users against untrusted index overrides.

T09 · Insecure Skill Coding Practices

Note
Location
rtc_work/__main__.py:134
Finding

Terminal Control-Sequence Injection Through Untrusted Job Metadata

Content
View full analysis

Vulnerability Details

File Location: rtc_work/__main__.py:134-141 and rtc_work/__main__.py:154-162
Vulnerability Type: Unsanitized terminal output
Risk Level: Low

Vulnerable Code

rtc_work/__main__.py:134-141:

python
def cmd_jobs(args):
    node = args.node or NODE_URL
    jobs = fetch_jobs(node, args.category or "", args.min_reward or 0.0)
    if not jobs:
        print(f"{C['d']}No open jobs.{C['x']}"); return 0
    for j in jobs:
        print(f"  {C['b']}{j.get('reward_rtc','?')} RTC{C['x']}  "
              f"[{j.get('category','?')}] {j.get('title','(untitled)')}  "
              f"{C['d']}{j.get('job_id','')[:16]}{C['x']}")

rtc_work/__main__.py:154-162:

python
for j in jobs:
    jid = j.get("job_id")
    if jid in seen:
        continue
    seen.add(jid)
    print(f"  {C['g']}match{C['x']} {j.get('reward_rtc')} RTC "
          f"[{j.get('category')}] {j.get('title')} {C['d']}{jid[:16]}{C['x']}")
    if args.auto and wallet:

Technical Analysis

Job attributes such as title, category, reward_rtc, and job_id originate from the configured remote node and are interpolated directly into terminal output. The program adds its own ANSI formatting but does not remove or escape terminal control characters contained in remote values.

A malicious job poster, compromised node, or attacker-controlled node selected through --node or the manifest can return strings containing escape sequences. Depending on terminal support, these sequences can alter colors, move the cursor, erase or overwrite displayed content, change a terminal title, create deceptive hyperlinks, or otherwise spoof the visible output.

This issue is terminal-output injection rather than shell-command injection: the values are passed to print and are not executed by a shell.

Attack Path

  1. An attacker creates job metadata containing ANSI escape sequences or other C0/C1 ter ...[truncated 960 chars]
Remediation
View remediation

Remediation Suggestions

  • Sanitize every server-controlled value before writing it to an interactive terminal.
  • Remove or visibly escape C0 and C1 control characters, including ESC, BEL, carriage return, backspace, and nonessential newlines.
  • Use a centralized helper for safe terminal rendering so all current and future output paths receive the same protection.
  • Consider rendering untrusted values with repr() or an equivalent escaped representation.
  • Validate response types before slicing or formatting fields such as job_id.
  • Add tests containing ANSI color changes, cursor movement, OSC hyperlinks, embedded carriage returns, and multiline job titles.
  • Provide an option to disable ANSI formatting entirely, especially when output is redirected to logs or automation.
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
Findings (12)

Rp1

Medium
Category
MCP Rug Pull
Confidence
88% confidence
Finding

The README instructs users to run uvx rtc-work without pinning an exact package version. This creates a supply-chain risk: users may fetch whatever version is current at execution time, including a compromised or typosquatted release, and the examples are copy-paste ready so the documentation directly influences execution behavior.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
88% confidence
Finding

The command example uses uvx rtc-work with no version constraint, so users executing it will resolve the latest available package at runtime. In a security-sensitive agent/tooling context, that increases exposure to malicious package updates or repository compromise, especially since this command is presented as a normal operational workflow.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
88% confidence
Finding

This documentation tells users to claim jobs via an unpinned uvx package execution, meaning the fetched tool version is not stable or authenticated beyond the package source. Because the tool interacts with wallets, job claims, and external nodes, a compromised future version could alter transaction-related behavior or exfiltrate sensitive configuration.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
90% confidence
Finding

The deliver example invokes an unpinned package in a workflow tied to job completion and on-chain reputation. If an attacker publishes or gains control of a later package version, users following the README could execute attacker-controlled code during a trusted operational step, making the documentation a practical vector for supply-chain compromise.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
87% confidence
Finding

Even for a read-only reputation lookup, uvx rtc-work without a pinned version causes users to execute whichever package release is current. The surrounding context makes this more dangerous than generic CLI docs because the tool is part of an agent/economic ecosystem and likely operates with wallet or node configuration present, increasing the value of a compromised package.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
91% confidence
Finding

The skill instructs users to run uvx rtc-work without pinning an exact package version. That allows whatever version is current in the package index at execution time to be installed and run, creating a supply-chain risk if a malicious or compromised release is published later. In this context the risk is elevated because the commands are meant to claim and deliver marketplace jobs, so users may run them with credentials, wallet access, or other sensitive agent context.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
91% confidence
Finding

The watch example references uvx rtc-work without a pinned version, so execution may fetch and run an unexpected future release. This is dangerous because package substitution or maintainer compromise can turn a routine polling command into arbitrary code execution on the user's machine. The skill context does not mitigate the issue; a long-running watch command may actually increase exposure if users normalize trusting the tool.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
92% confidence
Finding

The claim command uses an unpinned uvx rtc-work, exposing users to execution of whatever package version is latest when they run it. If the package or its distribution path is compromised, an attacker could execute arbitrary code at the moment a user interacts with job-market workflows, potentially accessing local secrets or session material. Because this command is tied to reserving jobs, users may be especially likely to run it in automation or privileged agent environments.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
92% confidence
Finding

The deliver example also invokes uvx rtc-work without version pinning, so the skill effectively delegates trust to the current state of the package repository at runtime. A malicious release could exfiltrate job contents, API tokens, wallet material, or alter delivery behavior while appearing to perform the expected task. Since this command may be used after work is completed, it could expose valuable artifacts or credentials associated with submission workflows.

Content

No source excerpt is available for this finding.

Intent-Code Divergence

Medium
Category
Not specified by scanner
Confidence
98% confidence
Finding

The module documentation states that the watch command is read-only, but the implementation can submit state-changing claim requests when --auto is enabled. This mismatch can cause operators or downstream automation to invoke watch under false safety assumptions, leading to unintended job reservations and external side effects.

Content

No source excerpt is available for this finding.

Autonomous Decision Making

Medium
Category
Excessive Agency
Confidence
85% confidence
Finding

Skill enables autonomous high-impact decisions without human-in-the-loop verification. Critical operations (destructive commands, financial transactions, data deletion) should require explicit user confirmation.

Content

Scanner excerpt · rtc_work/__main__.py (reported line 222)May include surrounding context.

python
p.add_argument("--node", default=None, help=f"node URL (default {NODE_URL})")
    p.add_argument("--manifest", default="agent.toml", help="agent manifest path")
    p.add_argument("--wallet", default=None, help="worker wallet (overrides manifest)")
    p.add_argument("--yes", "-y", action="store_true", help="skip confirmations")
    sub = p.add_subparsers(dest="cmd", required=True)

    s = sub.add_parser("jobs", help="list open jobs")

Unverifiable Dependency: setuptools has 10 known advisory(ies) (CVE-2013-1633 (Setuptools vulnerable to Man-in-the-middle attacks); CVE-2025-47273 (setuptools has a path traversal vulnerability in PackageIndex.download that lead); CVE-2024-6345 (setuptools vulnerable to Command Injection via package URL) +7 more), but the manifest does not pin a version, so it is unknown whether the installed release is affected

Low
Category
Supply Chain
Confidence
91% confidence
Finding

The build dependency is specified as "setuptools>=61" without an upper bound or exact pin, so the actual installed version is not verifiable from this manifest alone. Because setuptools has had multiple historical advisories, an environment resolving to a vulnerable version could expose the build process to known issues such as command injection or path traversal in affected releases.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.