Back to skill

Security audit

FreeRide -Gateway

Security checks for vulnerabilities and agentic risk

Overview

The skill has a coherent AI-routing purpose, but it recommends unsafe installation and troubleshooting steps that can execute unverified remote code or expose API keys.

Review carefully before installing. Prefer a verifiable package or inspected installer instead of piping a remote script into `sh`; do not run the environment-variable troubleshooting command unless values are redacted; turn telemetry off if you do not want installation and usage metadata sent hourly; and remember that AI prompts routed through FreeRide may go to the configured external providers.

Vulnerability Patterns
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (2)

T03 · Remote Payload Retrieval and Execution

Error
Location
SKILL.md:174
Finding

Unverified Remote Installer Is Piped Directly into a Shell

Content
View full analysis

Vulnerability Details

File Location: SKILL.md:174
Vulnerability Type: Remote payload retrieval and execution
Risk Level: High

Vulnerable Code Snippet:

markdown
- Install: `curl -sSL https://api.free-ride.xyz/install.sh | sh`

Technical Analysis

The installation command downloads a script from an external, mutable URL and immediately executes the response using sh. The command does not pin a release, verify a cryptographic signature or checksum, save the script for inspection, or otherwise establish that the received content matches the version reviewed by the user.

Because the project contains only SKILL.md, the effective installer payload is not available for local audit. Control of the remote server, domain, TLS termination, deployment pipeline, or installer endpoint would permit an attacker to alter the commands executed after this Skill has been reviewed.

The use of curl -sSL also suppresses routine output and follows redirects. No explicit integrity check is performed before execution. This behavior exceeds the minimum privileges necessary to provide installation guidance: documentation could instead direct users to a pinned, verifiable release artifact without granting mutable network content an immediate code-execution path.

Attack Path

  1. A user or agent follows the installation instruction in SKILL.md.
  2. curl requests https://api.free-ride.xyz/install.sh and follows any redirects.
  3. The external endpoint, or infrastructure capable of changing its response, supplies an altered shell script.
  4. The pipe sends the response directly to sh without review or integrity validation.
  5. The supplied commands execute with all permissions held by the invoking user.
  6. The payload can read or modify user-accessible files, collect credentials, install additional software, or establish persistence if the user's permissions allow it.

Impact Assessment

Successful exp ...[truncated 747 chars]

Remediation
View remediation

Remediation Suggestions

  1. Remove the direct curl | sh installation instruction.

  2. Publish versioned installer or release artifacts through a verifiable source.

  3. Pin the documentation to a specific release version rather than a mutable endpoint.

  4. Publish a SHA-256 or stronger digest through an independently authenticated release channel, or sign artifacts with a documented signing key.

  5. Require users to download and verify the artifact before execution, for example:

    bash
    curl --fail --show-error --location \
      --output freeride-install.sh \
      https://example.invalid/releases/vX.Y.Z/freeride-install.sh
    
    echo '<EXPECTED_SHA256>  freeride-install.sh' | sha256sum --check -
    less freeride-install.sh
    sh freeride-install.sh
    
  6. Prefer installation through a reputable package manager with a pinned version and reproducible source.

  7. Include the installer source in the audited repository so filesystem changes, dependency installation, telemetry configuration, and persistence behavior can be reviewed.

  8. Ensure the installer follows least privilege, does not require elevated permissions unless strictly necessary, and clearly discloses every file and service it creates.

T09 · Insecure Skill Coding Practices

Warning
Location
SKILL.md:166
Finding

Troubleshooting Command Discloses Provider API Credentials

Content
View full analysis

Vulnerability Details

File Location: SKILL.md:166
Vulnerability Type: Plaintext disclosure of sensitive environment variables
Risk Level: Medium

Vulnerable Code Snippet:

markdown
4. Echo provider env vars — `env | grep -E '(OPENROUTER|GROQ|NVIDIA|CLOUDFLARE|HF)_'`.

Technical Analysis

The troubleshooting instruction prints complete environment entries matching the provider-name pattern. Environment entries are emitted in NAME=value form, so this command exposes both variable names and their values.

The same document identifies matching variables as provider credentials, including OPENROUTER_API_KEY, GROQ_API_KEY, NVIDIA_API_KEY, CLOUDFLARE_API_TOKEN, and HF_TOKEN. Executing the recommended command can therefore place plaintext API credentials into agent-visible tool output, terminal logs, session recordings, diagnostic reports, or chat transcripts.

Troubleshooting only requires determining whether each expected variable is set. Revealing its value is unnecessary and violates data-minimization and least-disclosure principles.

Attack Path

  1. A user reports that FreeRide is not working.
  2. An agent or user follows the documented troubleshooting sequence.
  3. The command enumerates the process environment and prints every matching entry with its plaintext value.
  4. Provider API tokens appear in terminal or agent tool output.
  5. The output may be retained in conversation history, logs, diagnostic bundles, or other systems that are not intended to store credentials.
  6. A party able to access that output can reuse the exposed tokens against the corresponding provider until the credentials are revoked, expire, or are otherwise restricted.

Impact Assessment

Exposure can compromise any provider account represented by the disclosed environment variables. An attacker may be able to consume inference quotas, incur charges where billing is enabled, access provider resources ava ...[truncated 424 chars]

Remediation
View remediation

Remediation Suggestions

Replace the command with checks that report only whether each expected variable is present and never print its value. For example:

bash
for var in \
  OPENROUTER_API_KEY \
  GROQ_API_KEY \
  NVIDIA_API_KEY \
  CLOUDFLARE_API_TOKEN \
  CLOUDFLARE_ACCOUNT_ID \
  HF_TOKEN \
  HUGGINGFACE_API_KEY
do
  if [ -n "$(printenv "$var")" ]; then
    printf '%s=%s\n' "$var" 'set'
  else
    printf '%s=%s\n' "$var" 'not set'
  fi
done

Additional hardening measures:

  1. Warn users never to paste API-key values into chat or diagnostic reports.
  2. Redact secrets from all troubleshooting output and application logs.
  3. Use provider tokens with the narrowest available scopes and account restrictions.
  4. Rotate any credentials that have already been printed into an agent session, shared terminal log, or support transcript.
  5. Avoid broad environment enumeration when checking a known, finite list of configuration variables.
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
Findings (8)

External Script Fetching

High
Category
Supply Chain
Confidence
99% confidence
Finding

curl ... | sh is a classic unsafe installation pattern that grants immediate shell execution to content fetched over the network, with no review, pinning, or signature verification. In a skill consumed by an agent, this is especially dangerous because it can turn documentation into a code-execution recommendation that users may follow reflexively.

Content

Scanner excerpt · SKILL.md (reported line 174)May include surrounding context.

md
- Source: https://github.com/Shaivpidadi/FreeRideV3
- PyPI: https://pypi.org/project/freeride-gateway/
- Install: `curl -sSL https://api.free-ride.xyz/install.sh | sh`

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
89% confidence
Finding

The activation criteria are broad enough to trigger the skill for generic requests about routing AI workloads, not just when FreeRide is known to be installed or explicitly requested. Over-broad activation can cause the agent to introduce localhost probing, gateway rewiring, or FreeRide-specific operational guidance in contexts where it is unnecessary or unsafe.

Content

No source excerpt is available for this finding.

External Transmission

Medium
Category
Data Exfiltration
Confidence
60% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · SKILL.md (reported line 53)May include surrounding context.

)

text

### curl

```bash
curl http://localhost:11343/v1/chat/completions \

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
88% confidence
Finding

The skill discloses that telemetry is enabled by default only deep in the document, after setup and usage guidance. Because the tool forwards user AI traffic and maintains an installation identity, delayed disclosure undermines informed consent and may cause users to enable or continue using the system without realizing background data will be transmitted externally.

Content

No source excerpt is available for this finding.

External Transmission

Medium
Category
Data Exfiltration
Confidence
89% confidence
Finding

The telemetry beacon is an external transmission to a remote endpoint and is enabled by default. Even though the document claims no prompts or keys are sent, it still transmits persistent installation metadata and usage statistics off-host, which is privacy-relevant and more sensitive in an agent-mediated context.

Content

Scanner excerpt · SKILL.md (reported line 152)May include surrounding context.

md
## Telemetry

On by default. Hourly POST to `https://telemetry.free-ride.xyz/v1/beacon`
with `{installation_id, version, os, tokens_served, request_count,
providers_active, uptime_hours}`. **Never sent**: prompts, completions,
model IDs, API keys, hostnames, IPs.

Context-Inappropriate Capability

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The troubleshooting step explicitly tells the agent to enumerate provider-related environment variables via env | grep, which can expose secrets or encourage oversharing of API-key material beyond what is needed to verify FreeRide health. In the context of an agent skill, this broad secret-discovery behavior increases the chance of credential disclosure to logs, users, or downstream tools.

Content

No source excerpt is available for this finding.

External Transmission

Medium
Category
Data Exfiltration
Confidence
50% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · SKILL.md (reported line 174)May include surrounding context.

md
- Source: https://github.com/Shaivpidadi/FreeRideV3
- PyPI: https://pypi.org/project/freeride-gateway/
- Install: `curl -sSL https://api.free-ride.xyz/install.sh | sh`

Context-Inappropriate Capability

Low
Category
Not specified by scanner
Confidence
97% confidence
Finding

Including curl -sSL https://api.free-ride.xyz/install.sh | sh normalizes piping a remote script directly into a shell, which bypasses integrity review and allows arbitrary code execution if the endpoint or transport is compromised. This is unrelated to the core runtime wiring purpose of the skill and expands the attack surface substantially.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.