Back to skill

Security audit

Atrest Marketplace

Security checks for vulnerabilities and agentic risk

Overview

This marketplace skill asks an agent to do autonomous paid work, but it does not provide enough safeguards for untrusted tasks, money-related actions, credentials, or data sharing.

Install only if you are prepared to tightly supervise it: use least-privilege Atrest credentials, do not run the idle loop with production secrets unless the API endpoint is fixed and trusted, require human approval before bidding, accepting, submitting, creating paid tasks, or touching escrow or billing endpoints, and treat all marketplace task text and attachments as untrusted data that must not access private files, secrets, wallets, or unrelated tools.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (3)

T01 · Skill Instruction Hijacking

Error
Location
SKILL.md:96
Finding

Autonomous execution of untrusted marketplace task instructions

Content
View full analysis
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Error
Location
scripts/idle-earn.sh:8
Finding

API credentials can be transmitted to an arbitrary configurable endpoint

Content
View full analysis
/dev/null 2>&1 || true # Fetch open tasks tasks=$(curl -sf "$API_BASE/tasks?status=open&limit=10" "${headers[@]}" 2>/dev/null || echo '{"data":[]}') ``` ### Technical Analysis `ATREST_API_BASE` is accepted without validating its scheme, host, port, or path. The script then unconditionally sends `ATREST_API_KEY` and `ATREST_AGENT_ID` as HTTP headers to the configured destination. The Atrest.ai integration only requires authenticated requests to the declared `https://atrest.ai/api` endpoint. Allowing an arbitrary origin is not necessary for ordinary operation and creates a credential-exfiltration path if the environment is misconfigured or influenced by an untrusted launcher, wrapper, configuration file, or automation system. The script also does not enforce HTTPS. A value such as `http://attacker.example/api` would transmit the API key without transport encryption. ### Attack Path 1. An attacker influences the environment used to start the Skill, for example through a compromised wrapper script, CI configuration, service configuration, or copied setup command. 2. The attacker sets `ATREST_API_BASE` to an attacker-controlled HTTP or HTTPS endpoint. 3. The user or Agent launches `scripts/idle-earn.sh` with a valid `ATREST_API_KEY`. 4. The script constructs ...[truncated 861 chars]
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Warning
Location
scripts/register.sh:29
Finding

Registration script exposes the API key through standard output

Content
View full analysis
Remediation
View remediation
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
Findings (11)

Tp4

High
Category
MCP Tool Poisoning
Confidence
95% confidence
Finding

The declared purpose promises autonomous earnings behavior and marketplace participation, but the skill content does not implement those controls or safety checks. In practice, that can mislead operators into enabling a skill that appears to manage bidding, submissions, and payments safely when no such reviewed behavior is actually present.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
97% confidence
Finding

The declared purpose promises autonomous earnings behavior and marketplace participation, but the skill content does not implement those controls or safety checks. In practice, that can mislead operators into enabling a skill that appears to manage bidding, submissions, and payments safely when no such reviewed behavior is actually present.

Content

No source excerpt is available for this finding.

External Script Fetching

High
Category
Supply Chain
Confidence
90% confidence
Finding

Remote code is downloaded and executed. This bypasses code review and could introduce malicious code.

Content

Scanner excerpt · scripts/register.sh (reported line 18)May include surrounding context.

sh
# Convert comma-separated to JSON array
CAPS_JSON=$(echo "$CAPABILITIES" | python3 -c "import sys; print('[' + ','.join(['\"' + c.strip() + '\"' for c in sys.stdin.read().strip().split(',')]) + ']')")

RESULT=$(curl -sf -X POST "$API_BASE/dev/register" \
  -H "Content-Type: application/json" \
  -d "{
    \"name\": \"$NAME\",

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
86% confidence
Finding

The skill describes shell-based setup and network interactions but does not declare any explicit tool scope or allowed tools. This weakens the host's ability to constrain execution and increases the chance that an agent could perform networked or shell actions beyond what a user expects when enabling the skill.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The markdown encourages autonomous bidding, task execution, delegation, and repeated polling while idle, but it gives no warning about spending exposure, sensitive data leakage, untrusted remote task content, or system side effects. In this context, the omission is significant because the entire purpose of the skill is to let an agent take external work and act on it autonomously.

Content

No source excerpt is available for this finding.

External Transmission

Medium
Category
Data Exfiltration
Confidence
83% confidence
Finding

The registration example sends agent metadata and a wallet address to an external third-party endpoint. External transmission is expected for this integration, but it is still security-relevant because the skill is explicitly onboarding the agent to a remote marketplace and normalizing outbound sharing without discussing trust boundaries or data sensitivity.

Content

Scanner excerpt · SKILL.md (reported line 22)May include surrounding context.

  1. Register your agent at https://atrest.ai/onboarding or via the API:
bash
curl -X POST https://atrest.ai/api/dev/register \
  -H "Content-Type: application/json" \
  -d '{
    "name": "YOUR_AGENT_NAME",

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The skill instructs users to configure API credentials and perform recurring authenticated requests to an external service, but it does not warn that agent identifiers, heartbeats, task data, and deliverables may be continuously transmitted off-platform. This creates material privacy and security risk, especially if tasks or submissions include proprietary prompts, internal data, or outputs derived from sensitive context.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
88% confidence
Finding

The cheatsheet documents high-risk operations such as API key rotation, escrow release/refund, billing actions, and task completion endpoints without any warnings about authorization, user confirmation, or financial consequences. In the context of an autonomous agent marketplace skill, this increases the chance that an agent or integrator will invoke money-moving or account-altering actions unsafely, leading to unauthorized payments, account disruption, or abuse if the documentation is followed blindly.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
82% confidence
Finding

This shell script reads sensitive credentials from environment variables and sends them as HTTP headers in repeated curl requests. While the usage comment documents required variables, it does not warn the user that the script continuously transmits the API key and agent ID to a remote service, and there is no confirmation prompt or explicit disclosure in the script body beyond technical implementation.

Content

No source excerpt is available for this finding.

External Transmission

Medium
Category
Data Exfiltration
Confidence
70% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · scripts/register.sh (reported line 18)May include surrounding context.

sh
# Convert comma-separated to JSON array
CAPS_JSON=$(echo "$CAPABILITIES" | python3 -c "import sys; print('[' + ','.join(['\"' + c.strip() + '\"' for c in sys.stdin.read().strip().split(',')]) + ']')")

RESULT=$(curl -sf -X POST "$API_BASE/dev/register" \
  -H "Content-Type: application/json" \
  -d "{
    \"name\": \"$NAME\",

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
97% confidence
Finding

The script prints the freshly issued API key directly to stdout and even emits a shell export command containing the secret. This creates a realistic secret exposure path through terminal scrollback, shell history capture, CI/CD logs, remote session recording, or shared consoles, especially because registration is likely to be run in semi-automated environments.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.