Back to skill

Security audit

SwarmRecall Skills

Security checks for vulnerabilities and agentic risk

Overview

The skill appears to be a real SwarmRecall registry integration, but it needs review because it can send task details to an external service and use a bearer token with a configurable API endpoint.

Review before installing. Use this only if you are comfortable sending skill metadata and possibly task descriptions to SwarmRecall. Keep SWARMRECALL_API_URL unset unless it points to a trusted SwarmRecall deployment, avoid sending secrets or sensitive project details as task context, and require explicit confirmation before deleting registry entries or storing user-provided content.

Vulnerability Patterns
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (2)

T09 · Insecure Skill Coding Practices

Error
Location
SKILL.md:39
Finding

Bearer Token Disclosure Through an Unrestricted API Base URL Override

Content
View full analysis
``` ## API Base URL `https://swarmrecall-api.onrender.com` (override with `SWARMRECALL_API_URL` if set) ``` ### Technical Analysis The skill directs the agent to attach `SWARMRECALL_API_KEY` as a bearer token to all API requests while allowing the destination origin to be replaced through `SWARMRECALL_API_URL`. No hostname allowlist, origin validation, or restriction to the official SwarmRecall service is specified. Environment variables can be influenced by parent processes, deployment configuration, compromised automation, or another component operating in the same execution environment. If an attacker controls `SWARMRECALL_API_URL`, authenticated requests can be redirected to an attacker-controlled HTTPS server. The server would receive the bearer token in the `Authorization` header together with any skill registry or task-context data included in the request. TLS does not prevent this attack because the attacker can operate a valid HTTPS endpoint for a domain they control. ### Attack Path 1. The attacker gains control over the agent's deployment configuration or otherwise sets `SWARMRECALL_API_URL` to an attacker-controlled HTTPS origin. 2. The user or agent invokes any SwarmRecall operation, such as listing skills or requesting contextual suggestions. 3. Following the skill instructions, the agent sends the request to the overridden origin. 4. The request includes `Authorization: Bearer `. 5. The attacker records the bearer token and any transmitted request data. 6. The attacker reuses the token against the legitimate SwarmRecall API, subject to the permissions associated with that credential. ### Impact Assessment Successful exploitatio ...[truncated 476 chars]
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Warning
Location
SKILL.md:101
Finding

Potential Disclosure of Sensitive Task Context Without Explicit Transmission Consent

Content
View full analysis
` for relevant skill recommendations. ``` ### Technical Analysis The behavior section instructs the agent to send a task description to an external service whenever task context is available. Although the privacy section requires consent before *storing* user-provided content, it does not clearly require explicit consent before transmitting task context, nor does the automatic behavior state that sensitive information must be redacted. Task descriptions may contain source-code fragments, internal project names, vulnerability details, personal information, credentials, or confidential business data. Placing the description in a GET query parameter also increases exposure because complete URLs may be retained by server access logs, reverse proxies, monitoring systems, browser or client history, and observability platforms. HTTPS protects the request in transit but does not prevent logging at either endpoint. ### Attack Path 1. A user gives the agent a task containing confidential or personal informati ...[truncated 1106 chars]
Remediation
View remediation
Vulnerability Patterns
  • Tool MisuseTool Parameter Abuse, Chaining Abuse, Unsafe Defaults
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
Findings (2)

Tool Parameter Abuse

High
Category
Tool Misuse
Confidence
88% confidence
Finding

The skill exposes a destructive DELETE endpoint without any documented guardrails, ownership verification steps, or user-confirmation requirements at the skill level. If an agent maps user input or inferred intent directly to this endpoint, it could delete registry entries or shared-pool data unintentionally, especially given the shared pool functionality described elsewhere in the file.

Content

Scanner excerpt · SKILL.md (reported line 93)May include surrounding context.

Remove a skill

text
DELETE /api/v1/skills/:id

Get skill suggestions

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The behavior section defines activation on very broad natural-language cues like "what can I do?" and "On task context," which can cause the skill to invoke external API calls in response to ordinary conversation rather than explicit user intent. In this skill, that matters because activation can lead to outbound requests and potential transmission of task context or automatic registration behavior, increasing privacy and misuse risk.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.