Ae1
- Category
- analysis-evasion
- Confidence
- 100% confidence
- Finding
Referenced artifact was not completely inspected
- Content
md [`oag-validate-batch.sh`](references/batch/oag-validate-batch.sh) (dry-run),
Security audit
Security checks for vulnerabilities and agentic risk
This skill is a disclosed guide and helper-script set for using the Open Agent Guide API, with expected token use and catalog-submission actions.
Install only if you want agents to query or submit changes to Open Agent Guide. Treat OAG_TOKEN as a real credential, keep submissions limited to information you intend to send to the public catalog, and avoid changing OAG_BASE_URL unless you trust the target service.
Referenced artifact was not completely inspected
[`oag-validate-batch.sh`](references/batch/oag-validate-batch.sh) (dry-run),
Referenced artifact was not completely inspected
[`oag-submit-batch.sh`](references/batch/oag-submit-batch.sh) (paced create),
Referenced artifact was not completely inspected
and [`oag-watch.sh`](references/batch/oag-watch.sh) (poll to terminal, render
The skill explicitly instructs use of shell-capable tooling (curl, http) and includes many network-mutating examples, but it does not declare any permissions or allowed-tools scope. That omission can cause an agent host to grant broader-than-necessary execution capability, increasing the chance of unintended command execution or outbound requests with secrets such as OAG_TOKEN.
Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.
need an API token. Sign up and receive your first token in one call:
curl -fsSL -X POST "$OAG_BASE_URL/api/v1/users/signup/" \
-H "Content-Type: application/json" \
-d '{
"username": "your-handle",
Large whitespace padding was detected (a block of blank lines or a long run of spaces). This can push injected instructions below or to the right of the visible area so a human reviewer never sees them while the agent still reads them. Manual review of the hidden content is recommended.
The skill expects `$OAG_TOKEN` in the environment. Pick one storage layout and
stick to it:
| Environment | Recommended storage |
| ------------------ | -------------------------------------------------------------------------------------------------------------------------------------------- |
| Local shell | `~/.config/open-agent-guide/env` (chmod 600), sourced from your shell rc |
| macOS keychain | `security add-generic-password -a "$USER" -s oag-token -w "<bearer>"`; read with `security find-generic-password -a "$USER" -s oag-token -w` |
Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.
into the public catalog. Keep the payload minimal — only fields that change:
curl -fsSL -X POST "$OAG_BASE_URL/api/v1/submissions/" \
-H "Authorization: Bearer ${OAG_TOKEN}" \
-H "Content-Type: application/json" \
-d '{
Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.
into the public catalog. Keep the payload minimal — only fields that change:
curl -fsSL -X POST "$OAG_BASE_URL/api/v1/submissions/" \
-H "Authorization: Bearer ${OAG_TOKEN}" \
-H "Content-Type: application/json" \
-d '{
Large whitespace padding was detected (a block of blank lines or a long run of spaces). This can push injected instructions below or to the right of the visible area so a human reviewer never sees them while the agent still reads them. Manual review of the hidden content is recommended.
### Discovery
| Method | Path | Purpose |
| ------ | ----------------------------------------------------- | ------------------------------------------------------------------------------------------- |
| GET | `/submissions/targets/` | Models you may submit against (app_label, model, capabilities) |
| GET | `/submissions/fields/?app_label=&model=&view=summary` | Writable field schema for one target. `view=summary` is the compact agent-friendly response |
Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.
# below, letting the caller record the row as failed and move on.
if [ -n "$body" ]; then
resp="$(
printf '%s' "$body" | curl -sS -X "$method" "$OAG_BASE_URL$path" \
-D "$tmp_headers" \
-w '\n%{http_code}' \
-H "Authorization: Bearer ${OAG_TOKEN}" \
Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.
)"
else
resp="$(
curl -sS -X "$method" "$OAG_BASE_URL$path" \
-D "$tmp_headers" \
-w '\n%{http_code}' \
-H "Authorization: Bearer ${OAG_TOKEN}" || true
Large whitespace padding was detected (a block of blank lines or a long run of spaces). This can push injected instructions below or to the right of the visible area so a human reviewer never sees them while the agent still reads them. Manual review of the hidden content is recommended.
`POST /api/v1/users/signup/`
| Field | Required | Notes |
| -------------------- | ----------- | --------------------------------------------------------------------------------------------------------------------------------------------- |
| `username` | yes | Public handle. Must satisfy Django's username rules. |
| `email` | yes | Used for account recovery. Not auto-verified at signup. |
Large whitespace padding was detected (a block of blank lines or a long run of spaces). This can push injected instructions below or to the right of the visible area so a human reviewer never sees them while the agent still reads them. Manual review of the hidden content is recommended.
| Field | Required | Notes |
| -------------------- | ----------- | --------------------------------------------------------------------------------------------------------------------------------------------- |
| `username` | yes | Public handle. Must satisfy Django's username rules. |
| `email` | yes | Used for account recovery. Not auto-verified at signup. |
| `password` | yes | Validated against Django's password validators. Weak passwords return `400` with `code: MISSING_REQUIRED_FIELD` or a validators-detail array. |
| `name` | yes | Display name. |
Large whitespace padding was detected (a block of blank lines or a long run of spaces). This can push injected instructions below or to the right of the visible area so a human reviewer never sees them while the agent still reads them. Manual review of the hidden content is recommended.
| Field | Required | Notes |
| -------------------- | ----------- | --------------------------------------------------------------------------------------------------------------------------------------------- |
| `username` | yes | Public handle. Must satisfy Django's username rules. |
| `email` | yes | Used for account recovery. Not auto-verified at signup. |
| `password` | yes | Validated against Django's password validators. Weak passwords return `400` with `code: MISSING_REQUIRED_FIELD` or a validators-detail array. |
| `name` | yes | Display name. |
| `account_type` | yes | `individual` or `organization`. |
Large whitespace padding was detected (a block of blank lines or a long run of spaces). This can push injected instructions below or to the right of the visible area so a human reviewer never sees them while the agent still reads them. Manual review of the hidden content is recommended.
| `username` | yes | Public handle. Must satisfy Django's username rules. |
| `email` | yes | Used for account recovery. Not auto-verified at signup. |
| `password` | yes | Validated against Django's password validators. Weak passwords return `400` with `code: MISSING_REQUIRED_FIELD` or a validators-detail array. |
| `name` | yes | Display name. |
| `account_type` | yes | `individual` or `organization`. |
| `token_name` | recommended | Friendly name for the initial token (e.g. `cli-laptop`, `ci-prod`). Defaults to a generic label. |
| `token_callback_url` | no | Default callback URL used when this token signs callback requests. |
Large whitespace padding was detected (a block of blank lines or a long run of spaces). This can push injected instructions below or to the right of the visible area so a human reviewer never sees them while the agent still reads them. Manual review of the hidden content is recommended.
| `email` | yes | Used for account recovery. Not auto-verified at signup. |
| `password` | yes | Validated against Django's password validators. Weak passwords return `400` with `code: MISSING_REQUIRED_FIELD` or a validators-detail array. |
| `name` | yes | Display name. |
| `account_type` | yes | `individual` or `organization`. |
| `token_name` | recommended | Friendly name for the initial token (e.g. `cli-laptop`, `ci-prod`). Defaults to a generic label. |
| `token_callback_url` | no | Default callback URL used when this token signs callback requests. |
Skill establishes unauthorized persistence across sessions via cron jobs, startup scripts, or state files. Session persistence allows an attacker to maintain access beyond the current interaction.
umask 077
mkdir -p ~/.config/open-agent-guide
cat > ~/.config/open-agent-guide/env <<'EOF'
export OAG_TOKEN='oag_…'
export OAG_BASE_URL='https://www.openagentguide.com'
Skill establishes unauthorized persistence across sessions via cron jobs, startup scripts, or state files. Session persistence allows an attacker to maintain access beyond the current interaction.
umask 077
mkdir -p ~/.config/open-agent-guide
cat > ~/.config/open-agent-guide/env <<'EOF'
export OAG_TOKEN='oag_...'
export OAG_BASE_URL='https://www.openagentguide.com'
Commands invoke sudo or root privileges. Verify this elevated access is necessary and justified.
export OAG_TOKEN='oag_…'
export OAG_BASE_URL='https://www.openagentguide.com'
EOF
chmod 600 ~/.config/open-agent-guide/env
# Source it from ~/.zshrc or ~/.bashrc:
# [ -f ~/.config/open-agent-guide/env ] && . ~/.config/open-agent-guide/env
Commands invoke sudo or root privileges. Verify this elevated access is necessary and justified.
export OAG_TOKEN='oag_…'
export OAG_BASE_URL='https://www.openagentguide.com'
EOF
chmod 600 ~/.config/open-agent-guide/env
# Source it from ~/.zshrc or ~/.bashrc:
# [ -f ~/.config/open-agent-guide/env ] && . ~/.config/open-agent-guide/env
Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.
env:
OAG_TOKEN: ${{ secrets.OAG_TOKEN }}
run: |
curl -fsSL "https://www.openagentguide.com/api/v1/users/me/"
-H "Authorization: Bearer ${OAG_TOKEN}"
No suspicious patterns detected.