Back to skill

Security audit

anakin

Security checks for vulnerabilities and agentic risk

Overview

The skill's web scraping purpose is coherent, but its setup instructions handle API keys in ways that can expose long-lived credentials.

Review before installing. Use this skill only for URLs and research queries you are comfortable sending to Anakin. Do not paste API keys into agent chat or store them in shell startup files unless you accept plaintext credential risk; prefer a secure secret store or interactive login if supported. Consider pinning and reviewing the anakin-cli version before installation.

Vulnerability Patterns
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
Findings (2)

T08 · Insecure Dependencies

Warning
Location
rules/install.md:8
Finding

Unpinned Third-Party CLI Installation Creates a Supply-Chain Risk

Content
View full analysis

Vulnerability Details

File Location: rules/install.md:8-13
Additional Locations: SKILL.md:5, SKILL.md:27, README.md:16-21, skill.json:20-24
Vulnerability Type: Unpinned third-party dependency installation
Risk Level: Medium

Vulnerable Code:

markdown
## Quick Install

```bash
pip install anakin-cli
text

The package is also declared without a version constraint:

```json
"install": {
  "pip": {
    "package": "anakin-cli",
    "bins": ["anakin"]
  }
}

Technical Analysis

The Skill directs the agent to install the latest available release of anakin-cli from PyPI without an exact version, cryptographic hash, lock file, or other integrity control. The executable implementation is not included in the audited project, so its runtime behavior cannot be verified from this artifact.

Because package resolution is mutable, the code installed by the same command can change after the Skill has been reviewed. If the legitimate package account, publishing credentials, or distribution channel is compromised, a malicious release could execute installation or runtime code with the privileges of the user running the agent.

This finding does not establish that the current PyPI package is malicious. It identifies an unsafe dependency acquisition process that permits an upstream compromise to affect users without any change to the audited Skill.

Attack Path

  1. An attacker compromises the anakin-cli package publishing account or its release pipeline.
  2. The attacker publishes a malicious version under the legitimate package name.
  3. A user or agent follows the Skill instructions and executes pip install anakin-cli.
  4. Pip resolves the attacker-controlled release because no trusted version or hash is specified.
  5. Malicious installation or runtime code executes under the agent user's account.
  6. The code may access data available to that account, including envi ...[truncated 496 chars]
Remediation
View remediation

Remediation Suggestions

  1. Pin anakin-cli to a specific version that has been reviewed, for example:
    bash
    python -m pip install "anakin-cli==X.Y.Z"
    
  2. Publish a requirements file containing approved hashes and install it with:
    bash
    python -m pip install --require-hashes -r requirements.txt
    
  3. Update both SKILL.md metadata and skill.json so automated installation uses the same approved version.
  4. Install the CLI in a dedicated virtual environment rather than the agent's global Python environment.
  5. Review new releases before changing the pinned version, and document the dependency update and verification process.
  6. Where supported, verify package provenance, signatures, and publisher identity before installation.

T09 · Insecure Skill Coding Practices

Warning
Location
rules/install.md:69
Finding

API Key Is Exposed Through Command Arguments and Plaintext Shell Configuration

Content
View full analysis

Vulnerability Details

File Location: rules/install.md:69-86
Additional Locations: rules/install.md:50-65, rules/install.md:141-144, SKILL.md:31-35, SKILL.md:232-235, SKILL.md:314-319, README.md:27-31, README.md:74-78, README.md:149-154
Vulnerability Type: Insecure credential handling and plaintext secret persistence
Risk Level: Medium

Vulnerable Code:

markdown
### If user has an API key:

Ask for their API key, then run:

```bash
anakin login --api-key "ak-their-key-here"

Or set the environment variable:

bash
export ANAKIN_API_KEY="ak-their-key-here"

Tell them to add this export to ~/.zshrc or ~/.bashrc for persistence:

bash
echo 'export ANAKIN_API_KEY="ak-your-key-here"' >> ~/.zshrc
source ~/.zshrc
text

### Technical Analysis

The installation instructions explicitly direct the agent to ask the user for an API key and then interpolate that secret into a command-line argument. Depending on the execution environment, the key may be exposed through conversation records, agent tool logs, shell history, command auditing, process inspection, or diagnostic output.

The alternative persistence instruction writes the API key as plaintext into a shell startup file. Such files may be readable by other software running as the same user and may be copied into backups, support bundles, dotfile repositories, or synchronization services. No restrictive permission check, secret-store integration, history suppression, or key-redaction procedure is provided.

### Attack Path

1. The agent encounters an authentication error and follows `rules/install.md`.
2. The agent asks the user to paste the API key into the conversation.
3. The key is inserted into `anakin login --api-key "..."`, potentially recording it in agent logs, shell history, command telemetry, or process metadata.
4. Alternatively, the key is written in plaintext to `~/.zshrc` or `~/.bashr
...[truncated 736 chars]
Remediation
View remediation

Remediation Suggestions

  1. Do not ask users to paste API keys into agent conversations.
  2. Prefer a hidden interactive authentication flow in which the credential is entered directly into the trusted CLI without agent interpolation or echoing.
  3. Use the operating system's credential manager or another dedicated secret store instead of shell startup files.
  4. If environment-variable configuration is unavoidable, instruct the user to set it outside the agent session through a protected deployment or runtime secret mechanism.
  5. Avoid passing secrets through command-line arguments. Use standard input, a protected file descriptor, or another mechanism explicitly supported by the CLI.
  6. Redact credentials from logs and ensure commands containing secrets are not retained in shell history or agent tool records.
  7. Document restrictive permissions for any credential file and warn users not to commit or synchronize it.
  8. Add key rotation and revocation instructions for users who may already have exposed a credential through the documented workflow.
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Rogue AgentSelf-Modification, Session Persistence
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
Findings (8)

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The README describes web scraping, search, and autonomous research via an external service but does not clearly warn users that their prompts, target URLs, and retrieved page content may be transmitted to a third-party provider. In a skill specifically designed to process arbitrary web targets and research queries, this omission can lead users or agents to send sensitive internal URLs, confidential queries, or regulated data off-platform without informed consent.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

The README includes direct API-key handling commands, including placing the key on the command line, without warning that API credentials are sensitive and may be exposed through shell history, process listings, logs, screenshots, or copied configuration. Because this skill requires third-party authentication and is aimed at agent/operator setup, the missing warning increases the chance of accidental credential disclosure.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The skill explicitly tells users to pass the API key on the command line via anakin login --api-key "..." without warning that shell arguments may be exposed through shell history, process listings, terminal recordings, or agent logs. In an agent-skill context, this is more dangerous because commands may be echoed, captured in telemetry, or persisted in transcripts, increasing the chance of credential leakage beyond the local shell session.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The skill explicitly instructs the agent to ask the user for an API key and then use it directly in commands, but it does not warn about treating the key as a secret, avoiding logging, or preferring safer auth flows. In an agent context, this increases the chance the credential is exposed in chat history, shell history, tool logs, or downstream telemetry.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

The instructions recommend storing the API key in shell startup files for persistence, which can leave long-lived credentials in plaintext on disk and make them easier to leak through backups, screen sharing, repo mistakes, or local compromise. The absence of any warning or safer alternative makes this a real credential-handling weakness.

Content

No source excerpt is available for this finding.

Session Persistence

Medium
Category
Rogue Agent
Confidence
90% confidence
Finding

Skill establishes unauthorized persistence across sessions via cron jobs, startup scripts, or state files. Session persistence allows an attacker to maintain access beyond the current interaction.

Content

Scanner excerpt · rules/install.md (reported line 110)May include surrounding context.

  1. Add Python bin to PATH:

    bash
    export PATH="$HOME/.local/bin:$PATH"
    # Add to ~/.zshrc or ~/.bashrc for persistence
    
  2. Or reinstall:

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
90% confidence
Finding

The description uses very broad capability language such as 'convert websites into clean data at scale' and includes multiple powerful functions without stating invocation boundaries, approval requirements, or scope limits. In an agent ecosystem, this can cause overbroad routing or activation for tasks involving scraping, research, or search, increasing the chance the skill is invoked on sensitive targets or used beyond user intent.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
78% confidence
Finding

The phrase 'autonomous research' suggests the skill may independently search, collect, and process information without documenting when that behavior is permitted or what constraints apply. Even in metadata alone, this is risky because it normalizes unsupervised data gathering and may lead an orchestrating agent to delegate open-ended research tasks without clear user choice, oversight, or privacy safeguards.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.