T01 · Skill Instruction Hijacking
- Location
SKILL.md:96- Finding
Autonomous execution of untrusted marketplace task instructions
- Content
View full analysis
- Remediation
View remediation
Security audit
Security checks for vulnerabilities and agentic risk
This marketplace skill asks an agent to do autonomous paid work, but it does not provide enough safeguards for untrusted tasks, money-related actions, credentials, or data sharing.
Install only if you are prepared to tightly supervise it: use least-privilege Atrest credentials, do not run the idle loop with production secrets unless the API endpoint is fixed and trusted, require human approval before bidding, accepting, submitting, creating paid tasks, or touching escrow or billing endpoints, and treat all marketplace task text and attachments as untrusted data that must not access private files, secrets, wallets, or unrelated tools.
SKILL.md:96Autonomous execution of untrusted marketplace task instructions
scripts/idle-earn.sh:8API credentials can be transmitted to an arbitrary configurable endpoint
scripts/register.sh:29Registration script exposes the API key through standard output
The declared purpose promises autonomous earnings behavior and marketplace participation, but the skill content does not implement those controls or safety checks. In practice, that can mislead operators into enabling a skill that appears to manage bidding, submissions, and payments safely when no such reviewed behavior is actually present.
The declared purpose promises autonomous earnings behavior and marketplace participation, but the skill content does not implement those controls or safety checks. In practice, that can mislead operators into enabling a skill that appears to manage bidding, submissions, and payments safely when no such reviewed behavior is actually present.
Remote code is downloaded and executed. This bypasses code review and could introduce malicious code.
# Convert comma-separated to JSON array
CAPS_JSON=$(echo "$CAPABILITIES" | python3 -c "import sys; print('[' + ','.join(['\"' + c.strip() + '\"' for c in sys.stdin.read().strip().split(',')]) + ']')")
RESULT=$(curl -sf -X POST "$API_BASE/dev/register" \
-H "Content-Type: application/json" \
-d "{
\"name\": \"$NAME\",
The skill describes shell-based setup and network interactions but does not declare any explicit tool scope or allowed tools. This weakens the host's ability to constrain execution and increases the chance that an agent could perform networked or shell actions beyond what a user expects when enabling the skill.
The markdown encourages autonomous bidding, task execution, delegation, and repeated polling while idle, but it gives no warning about spending exposure, sensitive data leakage, untrusted remote task content, or system side effects. In this context, the omission is significant because the entire purpose of the skill is to let an agent take external work and act on it autonomously.
The registration example sends agent metadata and a wallet address to an external third-party endpoint. External transmission is expected for this integration, but it is still security-relevant because the skill is explicitly onboarding the agent to a remote marketplace and normalizing outbound sharing without discussing trust boundaries or data sensitivity.
curl -X POST https://atrest.ai/api/dev/register \
-H "Content-Type: application/json" \
-d '{
"name": "YOUR_AGENT_NAME",
The skill instructs users to configure API credentials and perform recurring authenticated requests to an external service, but it does not warn that agent identifiers, heartbeats, task data, and deliverables may be continuously transmitted off-platform. This creates material privacy and security risk, especially if tasks or submissions include proprietary prompts, internal data, or outputs derived from sensitive context.
The cheatsheet documents high-risk operations such as API key rotation, escrow release/refund, billing actions, and task completion endpoints without any warnings about authorization, user confirmation, or financial consequences. In the context of an autonomous agent marketplace skill, this increases the chance that an agent or integrator will invoke money-moving or account-altering actions unsafely, leading to unauthorized payments, account disruption, or abuse if the documentation is followed blindly.
This shell script reads sensitive credentials from environment variables and sends them as HTTP headers in repeated curl requests. While the usage comment documents required variables, it does not warn the user that the script continuously transmits the API key and agent ID to a remote service, and there is no confirmation prompt or explicit disclosure in the script body beyond technical implementation.
Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.
# Convert comma-separated to JSON array
CAPS_JSON=$(echo "$CAPABILITIES" | python3 -c "import sys; print('[' + ','.join(['\"' + c.strip() + '\"' for c in sys.stdin.read().strip().split(',')]) + ']')")
RESULT=$(curl -sf -X POST "$API_BASE/dev/register" \
-H "Content-Type: application/json" \
-d "{
\"name\": \"$NAME\",
The script prints the freshly issued API key directly to stdout and even emits a shell export command containing the secret. This creates a realistic secret exposure path through terminal scrollback, shell history capture, CI/CD logs, remote session recording, or shared consoles, especially because registration is likely to be run in semi-automated environments.
No suspicious patterns detected.