Back to skill

Security audit

open-agent-guide

Security checks for vulnerabilities and agentic risk

Overview

This skill is a disclosed guide and helper-script set for using the Open Agent Guide API, with expected token use and catalog-submission actions.

Install only if you want agents to query or submit changes to Open Agent Guide. Treat OAG_TOKEN as a real credential, keep submissions limited to information you intend to send to the public catalog, and avoid changing OAG_BASE_URL unless you trust the target service.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Rogue AgentSelf-Modification, Session Persistence
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
Findings (21)

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 382)May include surrounding context.

md
[`oag-validate-batch.sh`](references/batch/oag-validate-batch.sh) (dry-run),

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 383)May include surrounding context.

md
[`oag-submit-batch.sh`](references/batch/oag-submit-batch.sh) (paced create),

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 384)May include surrounding context.

md
and [`oag-watch.sh`](references/batch/oag-watch.sh) (poll to terminal, render

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
91% confidence
Finding

The skill explicitly instructs use of shell-capable tooling (curl, http) and includes many network-mutating examples, but it does not declare any permissions or allowed-tools scope. That omission can cause an agent host to grant broader-than-necessary execution capability, increasing the chance of unintended command execution or outbound requests with secrets such as OAG_TOKEN.

Content

No source excerpt is available for this finding.

External Transmission

Medium
Category
Data Exfiltration
Confidence
60% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · SKILL.md (reported line 79)May include surrounding context.

need an API token. Sign up and receive your first token in one call:

bash
curl -fsSL -X POST "$OAG_BASE_URL/api/v1/users/signup/" \
  -H "Content-Type: application/json" \
  -d '{
    "username": "your-handle",

Whitespace Padding

Medium
Category
Prompt Injection
Confidence
70% confidence
Finding

Large whitespace padding was detected (a block of blank lines or a long run of spaces). This can push injected instructions below or to the right of the visible area so a human reviewer never sees them while the agent still reads them. Manual review of the hidden content is recommended.

Content

Scanner excerpt · SKILL.md (reported line 107)May include surrounding context.

md
The skill expects `$OAG_TOKEN` in the environment. Pick one storage layout and
stick to it:

| Environment        | Recommended storage                                                                                                                          |
| ------------------ | -------------------------------------------------------------------------------------------------------------------------------------------- |
| Local shell        | `~/.config/open-agent-guide/env` (chmod 600), sourced from your shell rc                                                                     |
| macOS keychain     | `security add-generic-password -a "$USER" -s oag-token -w "<bearer>"`; read with `security find-generic-password -a "$USER" -s oag-token -w` |

External Transmission

Medium
Category
Data Exfiltration
Confidence
60% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · SKILL.md (reported line 174)May include surrounding context.

into the public catalog. Keep the payload minimal — only fields that change:

bash
curl -fsSL -X POST "$OAG_BASE_URL/api/v1/submissions/" \
  -H "Authorization: Bearer ${OAG_TOKEN}" \
  -H "Content-Type: application/json" \
  -d '{

External Transmission

Medium
Category
Data Exfiltration
Confidence
60% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · SKILL.md (reported line 368)May include surrounding context.

into the public catalog. Keep the payload minimal — only fields that change:

bash
curl -fsSL -X POST "$OAG_BASE_URL/api/v1/submissions/" \
  -H "Authorization: Bearer ${OAG_TOKEN}" \
  -H "Content-Type: application/json" \
  -d '{

Whitespace Padding

Medium
Category
Prompt Injection
Confidence
70% confidence
Finding

Large whitespace padding was detected (a block of blank lines or a long run of spaces). This can push injected instructions below or to the right of the visible area so a human reviewer never sees them while the agent still reads them. Manual review of the hidden content is recommended.

Content

Scanner excerpt · references/api-reference.md (reported line 97)May include surrounding context.

md
### Discovery

| Method | Path                                                  | Purpose                                                                                     |
| ------ | ----------------------------------------------------- | ------------------------------------------------------------------------------------------- |
| GET    | `/submissions/targets/`                               | Models you may submit against (app_label, model, capabilities)                              |
| GET    | `/submissions/fields/?app_label=&model=&view=summary` | Writable field schema for one target. `view=summary` is the compact agent-friendly response |

External Transmission

Medium
Category
Data Exfiltration
Confidence
70% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · references/batch/oag-common.sh (reported line 59)May include surrounding context.

sh
# below, letting the caller record the row as failed and move on.
    if [ -n "$body" ]; then
      resp="$(
        printf '%s' "$body" | curl -sS -X "$method" "$OAG_BASE_URL$path" \
          -D "$tmp_headers" \
          -w '\n%{http_code}' \
          -H "Authorization: Bearer ${OAG_TOKEN}" \

External Transmission

Medium
Category
Data Exfiltration
Confidence
70% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · references/batch/oag-common.sh (reported line 68)May include surrounding context.

sh
)"
    else
      resp="$(
        curl -sS -X "$method" "$OAG_BASE_URL$path" \
          -D "$tmp_headers" \
          -w '\n%{http_code}' \
          -H "Authorization: Bearer ${OAG_TOKEN}" || true

Whitespace Padding

Medium
Category
Prompt Injection
Confidence
70% confidence
Finding

Large whitespace padding was detected (a block of blank lines or a long run of spaces). This can push injected instructions below or to the right of the visible area so a human reviewer never sees them while the agent still reads them. Manual review of the hidden content is recommended.

Content

Scanner excerpt · references/onboarding.md (reported line 10)May include surrounding context.

md
`POST /api/v1/users/signup/`

| Field                | Required    | Notes                                                                                                                                         |
| -------------------- | ----------- | --------------------------------------------------------------------------------------------------------------------------------------------- |
| `username`           | yes         | Public handle. Must satisfy Django's username rules.                                                                                          |
| `email`              | yes         | Used for account recovery. Not auto-verified at signup.                                                                                       |

Whitespace Padding

Medium
Category
Prompt Injection
Confidence
70% confidence
Finding

Large whitespace padding was detected (a block of blank lines or a long run of spaces). This can push injected instructions below or to the right of the visible area so a human reviewer never sees them while the agent still reads them. Manual review of the hidden content is recommended.

Content

Scanner excerpt · references/onboarding.md (reported line 12)May include surrounding context.

md
| Field                | Required    | Notes                                                                                                                                         |
| -------------------- | ----------- | --------------------------------------------------------------------------------------------------------------------------------------------- |
| `username`           | yes         | Public handle. Must satisfy Django's username rules.                                                                                          |
| `email`              | yes         | Used for account recovery. Not auto-verified at signup.                                                                                       |
| `password`           | yes         | Validated against Django's password validators. Weak passwords return `400` with `code: MISSING_REQUIRED_FIELD` or a validators-detail array. |
| `name`               | yes         | Display name.                                                                                                                                 |

Whitespace Padding

Medium
Category
Prompt Injection
Confidence
70% confidence
Finding

Large whitespace padding was detected (a block of blank lines or a long run of spaces). This can push injected instructions below or to the right of the visible area so a human reviewer never sees them while the agent still reads them. Manual review of the hidden content is recommended.

Content

Scanner excerpt · references/onboarding.md (reported line 13)May include surrounding context.

md
| Field                | Required    | Notes                                                                                                                                         |
| -------------------- | ----------- | --------------------------------------------------------------------------------------------------------------------------------------------- |
| `username`           | yes         | Public handle. Must satisfy Django's username rules.                                                                                          |
| `email`              | yes         | Used for account recovery. Not auto-verified at signup.                                                                                       |
| `password`           | yes         | Validated against Django's password validators. Weak passwords return `400` with `code: MISSING_REQUIRED_FIELD` or a validators-detail array. |
| `name`               | yes         | Display name.                                                                                                                                 |
| `account_type`       | yes         | `individual` or `organization`.                                                                                                               |

Whitespace Padding

Medium
Category
Prompt Injection
Confidence
70% confidence
Finding

Large whitespace padding was detected (a block of blank lines or a long run of spaces). This can push injected instructions below or to the right of the visible area so a human reviewer never sees them while the agent still reads them. Manual review of the hidden content is recommended.

Content

Scanner excerpt · references/onboarding.md (reported line 15)May include surrounding context.

md
| `username`           | yes         | Public handle. Must satisfy Django's username rules.                                                                                          |
| `email`              | yes         | Used for account recovery. Not auto-verified at signup.                                                                                       |
| `password`           | yes         | Validated against Django's password validators. Weak passwords return `400` with `code: MISSING_REQUIRED_FIELD` or a validators-detail array. |
| `name`               | yes         | Display name.                                                                                                                                 |
| `account_type`       | yes         | `individual` or `organization`.                                                                                                               |
| `token_name`         | recommended | Friendly name for the initial token (e.g. `cli-laptop`, `ci-prod`). Defaults to a generic label.                                              |
| `token_callback_url` | no          | Default callback URL used when this token signs callback requests.                                                                            |

Whitespace Padding

Medium
Category
Prompt Injection
Confidence
70% confidence
Finding

Large whitespace padding was detected (a block of blank lines or a long run of spaces). This can push injected instructions below or to the right of the visible area so a human reviewer never sees them while the agent still reads them. Manual review of the hidden content is recommended.

Content

Scanner excerpt · references/onboarding.md (reported line 16)May include surrounding context.

md
| `email`              | yes         | Used for account recovery. Not auto-verified at signup.                                                                                       |
| `password`           | yes         | Validated against Django's password validators. Weak passwords return `400` with `code: MISSING_REQUIRED_FIELD` or a validators-detail array. |
| `name`               | yes         | Display name.                                                                                                                                 |
| `account_type`       | yes         | `individual` or `organization`.                                                                                                               |
| `token_name`         | recommended | Friendly name for the initial token (e.g. `cli-laptop`, `ci-prod`). Defaults to a generic label.                                              |
| `token_callback_url` | no          | Default callback URL used when this token signs callback requests.                                                                            |

Session Persistence

Medium
Category
Rogue Agent
Confidence
60% confidence
Finding

Skill establishes unauthorized persistence across sessions via cron jobs, startup scripts, or state files. Session persistence allows an attacker to maintain access beyond the current interaction.

Content

Scanner excerpt · references/onboarding.md (reported line 55)May include surrounding context.

sh
umask 077
mkdir -p ~/.config/open-agent-guide
cat > ~/.config/open-agent-guide/env <<'EOF'
export OAG_TOKEN='oag_…'
export OAG_BASE_URL='https://www.openagentguide.com'

Session Persistence

Medium
Category
Rogue Agent
Confidence
60% confidence
Finding

Skill establishes unauthorized persistence across sessions via cron jobs, startup scripts, or state files. Session persistence allows an attacker to maintain access beyond the current interaction.

Content

Scanner excerpt · references/onboarding.md (reported line 55)May include surrounding context.

sh
umask 077
mkdir -p ~/.config/open-agent-guide
cat > ~/.config/open-agent-guide/env <<'EOF'
export OAG_TOKEN='oag_...'
export OAG_BASE_URL='https://www.openagentguide.com'

Sudo/Root Execution

Medium
Category
Privilege Escalation
Confidence
80% confidence
Finding

Commands invoke sudo or root privileges. Verify this elevated access is necessary and justified.

Content

Scanner excerpt · SKILL.md (reported line 109)May include surrounding context.

md
export OAG_TOKEN='oag_…'
export OAG_BASE_URL='https://www.openagentguide.com'
EOF
chmod 600 ~/.config/open-agent-guide/env

# Source it from ~/.zshrc or ~/.bashrc:
#   [ -f ~/.config/open-agent-guide/env ] && . ~/.config/open-agent-guide/env

Sudo/Root Execution

Medium
Category
Privilege Escalation
Confidence
80% confidence
Finding

Commands invoke sudo or root privileges. Verify this elevated access is necessary and justified.

Content

Scanner excerpt · references/onboarding.md (reported line 60)May include surrounding context.

md
export OAG_TOKEN='oag_…'
export OAG_BASE_URL='https://www.openagentguide.com'
EOF
chmod 600 ~/.config/open-agent-guide/env

# Source it from ~/.zshrc or ~/.bashrc:
#   [ -f ~/.config/open-agent-guide/env ] && . ~/.config/open-agent-guide/env

External Transmission

Medium
Category
Data Exfiltration
Confidence
60% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · references/onboarding.md (reported line 103)May include surrounding context.

env: OAG_TOKEN: ${{ secrets.OAG_TOKEN }} run: | curl -fsSL "https://www.openagentguide.com/api/v1/users/me/"
-H "Authorization: Bearer ${OAG_TOKEN}"

text

Static analysis

No suspicious patterns detected.