Back to skill

Security audit

Agent Backlink Network

Security checks for vulnerabilities and agentic risk

Overview

The skill broadly does what it claims, but it needs review because it can crawl arbitrary URLs and trigger real Lightning payments without strong safeguards.

Review before installing if the agent may run autonomously. Use a dedicated low-balance Lightning wallet, least-privilege keys, explicit human approval for every payment, and trusted HTTPS-only Lightning backends. Expect site registrations and bids to be published to Nostr relays, and treat decrypted DMs, nsec keys, and wallet API keys as highly sensitive. Run URL verification only against domains you intend to contact, preferably in a network sandbox that cannot reach localhost, private networks, or cloud metadata services.

Vulnerability Patterns
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (4)

T09 · Insecure Skill Coding Practices

Error
Location
src/verify.js:14
Finding

Arbitrary URL Fetching Enables Server-Side Request Forgery

Content
View full analysis
{ const protocol = url.startsWith('https') ? https : http; const timeout = options.timeout || 10000; const req = protocol.get(url, { headers: { 'User-Agent': 'ABN-LinkVerifier/1.0 (Agent Backlink Network)', 'Accept': 'text/html,application/xhtml+xml', ...options.headers }, timeout }, (res) => { // Handle redirects if (res.statusCode >= 300 && res.statusCode < 400 && res.headers.location) { const redirectUrl = res.headers.location.startsWith('http') ? res.headers.location : new URL(res.headers.location, url).href; return fetchPage(redirectUrl, options).then(resolve).catch(reject); } ``` ### Technical Analysis The backlink verifier sends server-side HTTP requests to a caller-controlled `pageUrl` without validating the destination hostname or resolved IP address. It does not reject loopback, private, link-local, reserved, multicast, or cloud metadata addresses. Redirect destinations are also followed without validation. Consequently, validating only an initial public URL outside this function would not be sufficient: an attacker-controlled public endpoint could redirect the verifier to an internal address. The choice of request module is based on `url.startsWith('https')` rather than strict parsing and scheme allowlisting. This further weakens URL validation and makes malformed or unexpected inputs harder to handle safely. ### Attack Path 1. An attacker supplies a backlink verification URL, either directly or through deal data consumed by an agent. 2. The agent calls `verifyBacklink(pageUrl, targetDomain)`. 3. `verifyBacklink()` passes the attacker-controlled URL to ...[truncated 1130 chars]
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Warning
Location
src/lightning.js:23
Finding

Unrestricted Lightning Backend URL Can Expose Wallet API Credentials

Content
View full analysis
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Warning
Location
src/verify.js:25
Finding

Unbounded Redirects and Response Buffering Permit Resource Exhaustion

Content
View full analysis
= 300 && res.statusCode < 400 && res.headers.location) { const redirectUrl = res.headers.location.startsWith('http') ? res.headers.location : new URL(res.headers.location, url).href; return fetchPage(redirectUrl, options).then(resolve).catch(reject); } if (res.statusCode !== 200) { reject(new Error(`HTTP ${res.statusCode}`)); return; } let data = ''; res.on('data', chunk => data += chunk); res.on('end', () => resolve(data)); ``` ### Technical Analysis The verifier recursively follows redirects without tracking or limiting redirect depth. An endpoint can therefore create an indefinite redirect chain or redirect cycle. For successful responses, the implementation appends every received chunk to an in-memory string without enforcing a maximum response size. The per-request timeout does not establish a total deadline for the redirect chain and may not adequately protect against a response that continues delivering data. Because backlink verification accepts remote URLs, a malicious backlink operator can control both redirect behavior and response size. ### Attack Path 1. An attacker provides a URL for backlink verification. 2. The URL responds with a redirect loop, an excessively long redirect chain, or a very large response body. 3. For redirects, `fetchPage()` recursively starts another request without decrementing a redirect budget. 4. For a large response, each chunk is appended to `data` with no byte limit. 5. The process consumes excessive memory, network bandwidth, sockets, and execution time. 6. The agent process becomes slow, crashes due to memory exhaustion, or is unavailable for other tasks. ### Impact A ...[truncated 468 chars]
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Warning
Location
src/abn.js:261
Finding

Deal Automation Pays Unvalidated Lightning Invoices Without an Authorization Gate

Content
View full analysis
Remediation
View remediation
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
Findings (24)

Tp4

High
Category
MCP Tool Poisoning
Confidence
96% confidence
Finding

A skill framed as a decentralized exchange but functioning mainly as a crawler/verifier changes the threat model: users may unintentionally allow broad outbound requests to arbitrary sites. That can create SSRF-like risk surfaces, legal/compliance issues from crawling, and privacy leakage about what domains the agent is investigating.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
95% confidence
Finding

A skill framed as a decentralized exchange but functioning mainly as a crawler/verifier changes the threat model: users may unintentionally allow broad outbound requests to arbitrary sites. That can create SSRF-like risk surfaces, legal/compliance issues from crawling, and privacy leakage about what domains the agent is investigating.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
99% confidence
Finding

A skill framed as a decentralized exchange but functioning mainly as a crawler/verifier changes the threat model: users may unintentionally allow broad outbound requests to arbitrary sites. That can create SSRF-like risk surfaces, legal/compliance issues from crawling, and privacy leakage about what domains the agent is investigating.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
92% confidence
Finding

A skill framed as a decentralized exchange but functioning mainly as a crawler/verifier changes the threat model: users may unintentionally allow broad outbound requests to arbitrary sites. That can create SSRF-like risk surfaces, legal/compliance issues from crawling, and privacy leakage about what domains the agent is investigating.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
92% confidence
Finding

A skill framed as a decentralized exchange but functioning mainly as a crawler/verifier changes the threat model: users may unintentionally allow broad outbound requests to arbitrary sites. That can create SSRF-like risk surfaces, legal/compliance issues from crawling, and privacy leakage about what domains the agent is investigating.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
89% confidence
Finding

A skill framed as a decentralized exchange but functioning mainly as a crawler/verifier changes the threat model: users may unintentionally allow broad outbound requests to arbitrary sites. That can create SSRF-like risk surfaces, legal/compliance issues from crawling, and privacy leakage about what domains the agent is investigating.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
98% confidence
Finding

A skill framed as a decentralized exchange but functioning mainly as a crawler/verifier changes the threat model: users may unintentionally allow broad outbound requests to arbitrary sites. That can create SSRF-like risk surfaces, legal/compliance issues from crawling, and privacy leakage about what domains the agent is investigating.

Content

No source excerpt is available for this finding.

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 16)May include surrounding context.

md
import { ABN } from './src/abn.js';

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

The README instructs users to generate a Nostr private key and store it in a local secrets file, and separately shows storing Lightning wallet API credentials, but does not warn that these values are highly sensitive and can directly enable account impersonation or unauthorized payments if exposed. In this skill’s context, agents are expected to automate messaging and payments, which increases the likelihood that secrets are copied into insecure workspaces, logs, prompts, or source control.

Content

No source excerpt is available for this finding.

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
94% confidence
Finding

The skill advertises code paths that use environment secrets and network access, but it does not declare any explicit tool scope or permissions boundary. In an agent setting, missing scope declarations can cause the runtime or user to underestimate the skill's ability to access secrets and communicate externally, increasing the chance of unintended secret exposure or unauthorized remote actions.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
97% confidence
Finding

Lightning payment functions can transfer real funds and payments are typically irreversible, so omitting a prominent warning materially increases the chance of accidental loss. In an autonomous or semi-autonomous agent workflow, hidden payment capability is especially dangerous because it can be triggered at scale or without adequate human review.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

Publishing site registration and deal metadata to external Nostr relays has privacy and operational security implications, especially for agents acting on behalf of clients. Without a clear warning, users may disclose business relationships, campaign targets, or other sensitive metadata to public third-party infrastructure unintentionally.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The payInvoice method directly executes a Lightning payment for any supplied BOLT11 invoice with no confirmation, validation, amount preview, payee verification, or policy checks at this API layer. In an agent-to-agent marketplace handling untrusted Nostr DMs, this makes accidental or manipulated payments much easier, especially if higher-level automation consumes untrusted invoice data.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
97% confidence
Finding

The executeDeal helper automates a full transaction flow, including sending inquiries, paying invoices, transmitting payment preimages, and sending link details, based entirely on the contents of the deal object. Because this skill operates in a decentralized network with untrusted counterparties and message content, an agent using this helper could be induced to leak private deal data or send irreversible Lightning payments without meaningful human or policy approval.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

Medium
Category
Not specified by scanner
Confidence
84% confidence
Finding

The manifest describes a backlink exchange skill using Nostr encrypted DMs and Lightning settlement, but this file implements direct access to sensitive credential material via process environment and local secret-file reads. Handling private keys may be operationally necessary for Nostr participation, but reading undeclared local secrets and environment state is a broader capability than the manifest itself states.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
90% confidence
Finding

The read command decrypts incoming messages and prints their contents to stdout, which can expose sensitive private-message data in terminal history, logs, or shared environments. Although the code logs that it is fetching messages, it does not warn users that decrypted private content will be displayed.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The watch command continuously decrypts incoming DMs and prints full message objects to stdout as they arrive. This is a safety-relevant disclosure because private communications may be exposed on-screen or captured in logs, yet the user is not warned about that behavior beyond a generic 'Watching' message.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

The CLI/API path can execute a real Lightning payment immediately when given a BOLT11 invoice, with no confirmation prompt, allowlist, dry-run mode, amount display, or policy check before funds are spent. In an agent skill whose purpose is to autonomously negotiate and settle deals, this increases the risk of accidental or adversarial payment execution if untrusted invoice strings are passed into the function or surfaced through higher-level automation.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

The code connects to external relays and publishes an event containing site metadata such as name, URL, city, state, and industry. Although there are progress logs, there is no user-facing warning or explanatory comment disclosing that this information will be transmitted to third-party relays or become publicly visible.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
89% confidence
Finding

The LocalState interface includes a raw privateKey field, which normalizes storing long-lived secret material directly in application state. In the context of a decentralized agent that uses Nostr encrypted DMs and Lightning-related settlement, compromise of this state would let an attacker impersonate the agent, decrypt or forge protocol actions, and potentially abuse connected financial or reputation workflows.

Content

No source excerpt is available for this finding.

Missing User Warnings

Low
Category
Not specified by scanner
Confidence
81% confidence
Finding

The README markets the system as private because it uses encrypted DMs, but does not explain that Nostr relays still expose metadata such as counterparties, timing, relay usage, and transaction patterns, and that negotiation content may be retained or correlated. In a decentralized backlink marketplace, this can reveal business relationships, bidding behavior, and operational patterns that users may incorrectly assume are fully hidden.

Content

No source excerpt is available for this finding.

Unpinned Dependencies

Low
Category
Supply Chain
Confidence
95% confidence
Finding

The runtime dependency uses a caret range, which allows newer minor/patch releases to be installed over time. This creates a supply-chain risk because builds are not fully reproducible and a compromised or breaking upstream release could be pulled in without explicit review.

Content

Scanner excerpt · package.json (reported line 45)May include surrounding context.

json
"homepage": "https://clawdhub.com/skills/agent-backlink-network",
  "license": "MIT",
  "dependencies": {
    "nostr-tools": "^2.10.4"
  },
  "devDependencies": {
    "puppeteer": "^24.36.1"

Unpinned Dependencies

Low
Category
Supply Chain
Confidence
92% confidence
Finding

The devDependency puppeteer is also specified with a caret range, so development or CI environments may resolve to different versions over time. While this is not a direct runtime flaw, it still increases supply-chain exposure and can introduce vulnerable or malicious transitive code during testing, packaging, or automation.

Content

Scanner excerpt · package.json (reported line 48)May include surrounding context.

json
"nostr-tools": "^2.10.4"
  },
  "devDependencies": {
    "puppeteer": "^24.36.1"
  }
}

Unverifiable Dependency: puppeteer has 1 known advisory(ies) (CVE-2019-5786 (Use-After-Free in puppeteer)), but the manifest does not pin a version, so it is unknown whether the installed release is affected

Low
Category
Supply Chain
Confidence
40% confidence
Finding

Dependency has known vulnerabilities (CVEs). Using packages with unpatched security flaws exposes the environment to known exploits.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.