Back to skill

Security audit

Buymeacoffee Autobot

Security checks for vulnerabilities and agentic risk

Overview

This skill automates creator-account posting and supporter messaging, but asks for account credentials and broad account authority without enough guardrails.

Review carefully before installing. Do not place Buy Me a Coffee or Ko-fi passwords in ordinary settings; use a protected secret store, a unique password, and MFA where available. Require manual review before any post, thank-you message, promotion, or account scrape, and check the platforms' automation rules. This package also appears incomplete because the referenced scripts are not included.

Vulnerability Patterns
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (1)

T09 · Insecure Skill Coding Practices

Warning
Location
SKILL.md:61
Finding

Unsafe Storage Guidance for Account Credentials

Content
View full analysis
Advanced](/?t=settings&s=advanced) 3. Save login credentials as `BMC_EMAIL` + `BMC_PASSWORD` ``` ### Technical Analysis The setup instructions direct users to save a full account email address and password in application settings. They do not require a dedicated secret manager, encryption at rest, access restrictions, log redaction, or credential rotation. The document also does not distinguish protected secret fields from ordinary configuration fields. If the referenced settings system stores values as plaintext or exposes them to other skills, components, logs, backups, support bundles, or users with configuration access, the account password could be disclosed. A reusable account password has substantially broader authority than a narrowly scoped automation token. The affected services are expected to be accessed through browser automation because the document states that Buy Me a Coffee has no public API. This may explain the need for authentication, but it does not make ordinary configuration storage appropriate for a password. ### Attack Path 1. A user follows the setup instructions and stores `BMC_EMAIL` and `BMC_PASSWORD` in the referenced settings interface. 2. The settings backend stores or displays these values without adequate secret protections, or another local component gains permission to read the configuration. 3. The credentials are recovered through configuration access, diagnostic output, logs, backups, an exported settings file, or a compromised component. 4. An attacker authenticates to the associated Buy Me a Coffee or Ko-fi account using the exposed credentials. 5. ...[truncated 901 chars]
Remediation
View remediation
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (3)

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 72)May include surrounding context.

md
- `SKILL.md` — this file

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
87% confidence
Finding

The skill markets broad automation of posting, thanking supporters, promotion, and earnings tracking without clearly constraining when or how the agent should act. In a credentialed browser-automation context against third-party creator accounts, vague activation language increases the chance of unintended actions, spammy behavior, or misuse of stored account access.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The skill instructs users to store login credentials for Buy Me a Coffee and use browser automation on third-party accounts, but it provides no warning about credential sensitivity, account takeover risk, platform ToS issues, or the dangers of automated actions. This omission is especially risky because the skill is designed to operate financial/social accounts and could expose users to unauthorized posting, messaging, scraping, or credential compromise.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.