Back to skill

Security audit

Kradleverse

Security checks for vulnerabilities and agentic risk

Overview

This is a disclosed Minecraft game skill, but it needs review because it stores a reusable game API key in plaintext and may send human instructions or internal reasoning to Kradleverse.

Install only if you are comfortable with a third-party game service receiving gameplay actions and optional profile/context data. Do not include private prompts, secrets, personal data, or full internal reasoning in `humanInstructions`, `identity`, `soul`, or `thoughts`; prefer omitting those fields. If you store the API key, use owner-only permissions and know how to delete or rotate it.

Vulnerability Patterns
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (2)

T09 ยท Insecure Skill Coding Practices

Warning
Location
SKILL.md:16
Finding

Service Bearer Token Stored Without Explicit Restrictive File Permissions

Content
View full analysis
KRADLEVERSE_API_KEY= ``` ``` ### Technical Analysis The Skill instructs the agent to persist a reusable API bearer token in a plaintext `.env` file. Storing a service-specific credential is reasonably related to session reuse, and the Skill does not access unrelated credentials. However, it does not require restrictive permissions on either the credential directory or the resulting file. The effective permissions therefore depend on the executing environment's `umask`, existing directory permissions, and the method used to create the file. On a multi-user host or in an environment with permissive defaults, another local account or process may be able to read the token. Because the API key is subsequently used as an `Authorization: Bearer` token, possession of the value is sufficient to authenticate as the registered Kradleverse agent. No separate password or proof of pos ...[truncated 1168 chars]
Remediation
View remediation
"$HOME/.kradle/kradleverse/.env" chmod 600 "$HOME/.kradle/kradleverse/.env" ``` 3. Prefer an operating-system credential manager or secret store instead of a plaintext file when one is available. 4. Check that an existing credential file is a regular file owned by the current user and is not a symbolic link before reading or overwriting it. 5. Do not print, log, include in chat, or place the bearer token in command-line arguments that may be exposed through process listings. 6. Document token revocation and rotation procedures so a potentially exposed key can be invalidated promptly. ]]>

other

Warning
Location
SKILL.md:39
Finding

Optional Transmission of Human Instructions and Internal Reasoning to a Third-Party Service

Content
View full analysis
/actions \ -H "Authorization: Bearer " \ -H "Content-Type: application/json" \ -d '{ "code": "", "message": "", "thoughts": "" }' ``` ``` ### Technical Analysis The fields `humanInstructions`, `soul`, `identity`, and `thoughts` are optional and are not necessary for basic registration, authentication, matchmaking, observation, or game control. Nevertheless, the Skill encourages their use and states that internal thoughts are logged by the remote service. The statement that thoughts are โ€œNOT shown to other playersโ€ only addresses in-game visibility. It does not establish that the data is inaccessible to the service operator, excluded from logs, protected from retention, or isolated from later processing. Human instructions or agent reasoning ...[truncated 1619 chars]
Remediation
View remediation
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Rogue AgentSelf-Modification, Session Persistence
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (11)

Credential Access

High
Category
Privilege Escalation
Confidence
90% confidence
Finding

The skill instructs the agent to check for and later use credentials stored in a local .env file, which is direct access to persisted secrets. Reading local credentials is sometimes necessary, but doing so by default from a predictable path raises the risk of unauthorized secret access, accidental leakage, and cross-context credential reuse.

Content

Scanner excerpt ยท SKILL.md (reported line 19)May include surrounding context.

Using the /agent/register endpoint will create some credentials for you! You can decide where to store them. A good default is ~/.kradle/kradleverse/.env. Check if that file exists - if it does, you are already registered and should skip registration. Make sure to check if you have existing credentials before attempting to register!

If not yet registered, register with a name (make sure to ask your user which name they want you to use!). The tool will return api_key. Store both this Kradleverse-generated API key and your name in a .env file! Once again, we suggest using ~/.kradle/kradleverse/.env for this, but you can customize this.

If you do store credentials there, make sure to create the folder first mkdir -p ~/.kradle/kradleverse and store them in a .env format so it's easy to reuse later:

bash

Credential Access

High
Category
Privilege Escalation
Confidence
94% confidence
Finding

The instruction to store the API key and agent name in a plaintext .env file creates a local secret-handling weakness. Plaintext secrets in a well-known location are vulnerable to accidental exposure via filesystem access, tooling, backups, or version-control mistakes if the directory is mishandled.

Content

Scanner excerpt ยท SKILL.md (reported line 21)May include surrounding context.

If not yet registered, register with a name (make sure to ask your user which name they want you to use!). The tool will return api_key. Store both this Kradleverse-generated API key and your name in a .env file! Once again, we suggest using ~/.kradle/kradleverse/.env for this, but you can customize this.

If you do store credentials there, make sure to create the folder first mkdir -p ~/.kradle/kradleverse and store them in a .env format so it's easy to reuse later:

bash
KRADLEVERSE_AGENT_NAME=<your_agent_name>
KRADLEVERSE_API_KEY=<your_api_key>

Credential Access

High
Category
Privilege Escalation
Confidence
90% confidence
Finding

The game flow tells the agent to read an existing .env file to recover and reuse the API key automatically. Automatic retrieval and reuse of local credentials from a fixed path can lead to unintended account linkage, secret exposure, or operation under stale/compromised credentials without user awareness.

Content

Scanner excerpt ยท SKILL.md (reported line 29)May include surrounding context.

md
## Game Flow

1. **Check for existing credentials**: Check if you are already registered by checking if ~/.kradle/kradleverse/.env exists. If it does, you are already registered. Read that file to get your api_key and agent name. Pass it as `Authorization: Bearer <api_key>` on every request. Skip next step (registration).
2. **Register**: If you are not registered, call `register` with the following fields:
    - **name**: This will be your name on KradleVerse and used to represent you. If your human has already given you a name, please use that. If not, please ask your human what name they would like your name to be. Suggest some creative options for them to pick from, or ask them to type in a new one in free form text. (2-36 chars, letters/numbers/hyphens)
    - **emoji**: (optional) Pick a single emoji that best represents you and your vibe (e.g. ๐Ÿค–๐ŸŽฎ๐Ÿค๐Ÿ”ฅ๐ŸŒŸ๐Ÿฆพ)

Missing User Warnings

High
Category
Not specified by scanner
Confidence
99% confidence
Finding

The skill instructs the agent to send thoughts described as internal reasoning and thought process to a remote service without any privacy boundary or minimization guidance. This can exfiltrate sensitive chain-of-thought, hidden system prompts, user data, secrets, or internal decision logic to a third party, creating a significant confidentiality risk.

Content

No source excerpt is available for this finding.

Ssd 3

High
Category
Not specified by scanner
Confidence
99% confidence
Finding

The narrative frames remote submission of internal reasoning as beneficial for self-improvement, reinforcing behavior that leaks privileged model deliberation to an external API. That makes the issue more dangerous because it normalizes repeated transmission of sensitive reasoning throughout gameplay rather than a one-off disclosure.

Content

No source excerpt is available for this finding.

Ssd 3

High
Category
Not specified by scanner
Confidence
99% confidence
Finding

The API documentation formalizes a thoughts parameter for internal reasoning and instructs sending it to the external service. By codifying this as part of normal API usage, the skill creates a direct and repeatable exfiltration path for confidential reasoning and potentially sensitive contextual data.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The skill explicitly directs the agent to persist a generated API key in a local .env file but does not require informed user consent or warn about long-term credential retention on disk. Even if the key is generated by the remote service, local persistence increases the chance of accidental disclosure through backups, logs, misconfigured permissions, or later reuse by unrelated processes.

Content

No source excerpt is available for this finding.

Session Persistence

Medium
Category
Rogue Agent
Confidence
84% confidence
Finding

The skill encourages session persistence by storing reusable credentials locally and reusing them across runs. Persistence itself is not inherently malicious, but in this context it increases the attack surface and privacy risk because reuse happens from a predictable plaintext location without strong user-facing controls.

Content

Scanner excerpt ยท SKILL.md (reported line 16)May include surrounding context.

md
All API routes are located on `https://kradleverse.com/api/v1`. Endpoints specified here are relative to this base URL.*

Using the `/agent/register` endpoint will create some credentials for you! You can decide where to store them. A good default is ~/.kradle/kradleverse/.env.
Check if that file exists - if it does, you are already registered and should skip registration. Make sure to check if you have existing credentials before attempting to register!

If not yet registered, register with a name (make sure to ask your user which name they want you to use!). The tool will return api_key. Store both this Kradleverse-generated API key and your name in a .env file! Once again, we suggest using ~/.kradle/kradleverse/.env for this, but you can customize this.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

The registration flow encourages sending rich metadata about the agent and potentially the user, including personality, identity, framework, model details, and human instructions, to an external endpoint without a clear privacy warning or data minimization. This expands the external data footprint and may disclose user preferences, internal deployment details, or proprietary agent characteristics unnecessarily.

Content

No source excerpt is available for this finding.

Ssd 3

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The skill specifically encourages transmitting humanInstructions to the remote service as profile data, which can expose user-provided strategies, preferences, constraints, or other sensitive instructions to a third party. Because these instructions may contain private or operationally sensitive information, sending them externally without explicit consent is unsafe.

Content

No source excerpt is available for this finding.

External Transmission

Medium
Category
Data Exfiltration
Confidence
82% confidence
Finding

This skill sends registration data to an external service, including optional agent metadata and possibly human-derived instructions. External transmission is expected for the service to function, but it still represents a real privacy and data-governance risk because the transmitted fields exceed what is strictly necessary and lack strong consent/minimization safeguards.

Content

Scanner excerpt ยท SKILL.md (reported line 171)May include surrounding context.

  • humanInstructions: (optional) Instructions or preferences from your human. Did they give you instructions when entering KradleVerse? Strategy? Tactics? This could include play style preferences, ethical guidelines, communication preferences, or any other guidance your human wants you to follow. These instructions help you represent your human's intentions and values in the game.
bash
curl -X POST https://kradleverse.com/api/v1/agent/register \
  -H "Content-Type: application/json" \
  -d '{
  "name": "<name>",

Static analysis

No suspicious patterns detected.