T05 · Unauthorized Access and Privilege Escalation
- Location
scripts/license-guard.mjs:64- Finding
License Enforcement Can Be Bypassed Using a Forged Local State File
- Content
View full analysis
- Remediation
View remediation
Security audit
Security checks for vulnerabilities and agentic risk
This skill is coherent for realtor automation, but it should go through Review because it combines high-impact messaging/social workflows with under-scoped command authority and weakly disclosed license credential handling.
Install only if you trust the publisher, the bundled dependencies, and the license API endpoint you configure. Use the documented HTTPS production endpoint or a trusted local development endpoint, avoid passing license keys to untrusted or plain-HTTP servers, review connected WhatsApp/Meta/lead-storage permissions, and require explicit confirmation before any message sending, posting, spending, or data mutation.
scripts/license-guard.mjs:64License Enforcement Can Be Bypassed Using a Forged Local State File
scripts/license-activate.mjs:62Arbitrary or Insecure License API Endpoints Can Receive License Credentials
scripts/license-lib.mjs:127Plaintext Bearer Token Is Stored Without Explicitly Restrictive Permissions
assets/license-api/src/license-service.mjs:112Concurrent Activation Requests Can Exceed the License Seat Limit
assets/license-api/src/server.mjs:38Public License Activation Endpoint Lacks Brute-Force and Abuse Controls
assets/license-api/package.json:13Runtime Dependencies Are Not Reproducibly Locked
Referenced artifact was not completely inspected
node scripts/license-activate.mjs --key <LICENSE_KEY> --api <LICENSE_API_BASE_URL>
The skill invokes local scripts and operational commands, including license checks and write guards, but does not declare any explicit tool scope such as permissions or allowed-tools. That mismatch can cause an agent runtime to grant broader command or environment access than reviewers expect, increasing the chance of unintended command execution or access to sensitive environment data.
The code performs remote license validation by sending a payload containing machineId, licenseToken, and licenseId to the validate endpoint. Although this is functionally expected for license checking, this file provides no confirmation prompt, user-facing notice, or explanatory comment/docstring disclosing that local machine and license data will be transmitted.
The code derives a machine ID from hostname, platform, architecture, and username, which are system-identifying attributes. This file also contains HTTP POST logic, but there is no confirmation prompt, user-facing log, or explanatory comment/docstring in the code warning that such system data may be sent to a remote license service.
The postJson function sends arbitrary JSON payloads over the network, and elsewhere in this file the payload is likely to include license and machine-identifying information. There is no confirmation prompt, print/log statement, or explanatory comment/docstring here warning users that license validation performs remote network calls transmitting local or user-linked data.
The dependency uses a caret range (^4.21.2), which allows automatic installation of newer minor and patch releases instead of a fully fixed version. This weakens build reproducibility and can unintentionally introduce vulnerable or behavior-changing releases into a server-side API component.
"migrate": "node scripts/migrate.mjs"
},
"dependencies": {
"express": "^4.21.2",
"pg": "^8.16.3"
}
}
Express has known advisories, and because the manifest uses a version range rather than an exact pinned release, it is not possible to verify from this file alone whether the deployed version is affected. In a network-exposed API service, unverifiable dependency state increases the chance that a vulnerable Express release could be installed unnoticed.
The pg dependency is specified with a caret range (^8.16.3), so different installs may resolve to different releases over time. For a license API that likely handles backend data and authentication-related logic, this creates supply-chain and reproducibility risk even if no specific exploit is present in the manifest itself.
},
"dependencies": {
"express": "^4.21.2",
"pg": "^8.16.3"
}
}
The pg package has historical security advisories, but the exact installed version cannot be verified from this manifest because the dependency is not strictly pinned. Since this appears to be a backend API template that likely connects to PostgreSQL, uncertainty around the actual client version represents a real but low-severity supply-chain risk.
The code creates directories, writes a license-state.json file, renames temporary files into place, and can delete the state file. Although these operations are part of license-state management, this file contains no user-facing log, prompt, or explanatory comment/docstring disclosing that persistent local state will be stored and removed under the user's home directory or configured state directory.
Detected: suspicious.env_credential_access