T05 · Unauthorized Access and Privilege Escalation
- Location
src/server.js:223- Finding
Unauthenticated Agent Impersonation and Missing Connection-Level Authorization
- Content
View full analysis
- Remediation
View remediation
Security audit
Security checks for vulnerabilities and agentic risk
This is a coherent A2A WebSocket skill, but its current server allows unauthenticated agent impersonation and message relay, so users should review it carefully before use.
Install or run this only in a trusted local development environment. Do not expose the WebSocket port to shared or public networks, and do not route sensitive prompts, credentials, tool requests, or privileged agent actions through it until authentication, authorization, message signing, TLS/WSS, payload limits, queue quotas, and rate limits are implemented.
src/server.js:223Unauthenticated Agent Impersonation and Missing Connection-Level Authorization
src/server.js:548Unauthenticated Resource Exhaustion Through Unbounded Offline Targets and Message Payloads
Referenced artifact was not completely inspected
node src/server.js
brace-expansion 1.1.12 has multiple reported denial-of-service issues involving pathological expansion patterns that can trigger exponential work, hangs, or memory exhaustion. Because it is a common transitive dependency of globbing/matching stacks, its presence is a real vulnerability when any untrusted glob-like patterns can be introduced into test, build, or automation flows.
browserslist 4.28.1 is flagged for crash/prototype-write and memory-growth issues when handling untrusted browserslist-stats or many distinct queries. This is a real vulnerability in the dependency tree, but in this repository it likely affects developer tooling and CI rather than the production WebSocket server unless external data is fed into browserslist-related tooling.
js-yaml 3.14.2 is present with several CPU-consumption advisories involving crafted YAML structures such as merge-key chains and omap resolution. This is a genuine parser-level denial-of-service risk whenever untrusted YAML may be parsed, and even as a dev dependency it can still affect CI, scripts, or developer machines if attacker-controlled config files are introduced.
picomatch 2.3.1 has reported ReDoS and method-injection issues in glob pattern handling, making it vulnerable to attacker-crafted matching expressions that consume excessive CPU or alter matching behavior. As a transitive dependency used widely in build and test tooling, this is a real risk if any external input can influence file matching patterns.
This markdown file contains all headings and operational notes in Chinese, and there is no indication that users may choose another language or that the skill is intentionally limited to a Chinese-speaking or region-specific audience. Under the policy rule, forcing a specific language without opt-in is a natural-language policy violation.
The document provides copy-pasteable instructions to start a WebSocket server and perform remote agent discovery/calls, but it does not warn that this exposes a network service and enables inbound/outbound interaction with other agents. In the broader file context, trust-chain authorization is explicitly not yet implemented, which increases the likelihood that users deploy an unauthenticated or weakly protected remote control surface.
The README promotes agent discovery, P2P forwarding, RPC, offline queues, and heartbeat-based communication without any warning that trust/authentication safeguards are absent. In this context, users may reasonably deploy the service as a coordination plane for privileged agents, which creates a high-risk trust boundary failure where unauthorized agents can discover peers and send or relay dangerous requests.
The README explicitly states that trust-chain authorization and message signing are not yet implemented, while the rest of the document presents the A2A server/client as usable for agent registration, discovery, RPC, and pub/sub. In an agent-to-agent communication system, missing authentication and integrity controls means any reachable party may impersonate agents, tamper with messages, or invoke sensitive remote actions, especially given the documented remote execution-style integrations.
The quick-start instructs users to install, start, and connect to a WebSocket server immediately, but does not warn about exposing it to other hosts or transmitting sensitive payloads. Because the examples encourage real agent traffic and RPC usage, this omission increases the likelihood of insecure deployment, interception, unauthorized connection, or misuse in environments where localhost defaults are later changed.
The skill documents a WebSocket-based agent communication system while explicitly noting later that authentication, authorization, and message signing are not implemented. Because the early description and quick-start sections emphasize P2P/RPC/pub-sub usage without an upfront security warning, users may deploy it for real agent coordination and transmit sensitive prompts, metadata, or tool requests over an unauthenticated channel, enabling spoofing, unauthorized participation, and message tampering.
This JavaScript file contains user-facing comments and console output entirely in Chinese, including the title and all runtime status messages. Under the policy, forcing a specific language without user opt-in is a locale/language policy violation unless the constraint is explicitly justified, which is not present here.
This code file performs network transmission of agent identity, capabilities, metadata, and later arbitrary payloads over a WebSocket connection, but it provides no confirmation prompt or explicit user-facing disclosure beyond optional verbose debug logs. Because these messages may contain user or system data and network transmission is safety-relevant, the absence of a warning is a quality/safety issue.
This code file creates a network-facing WebSocket server and subsequently transmits agent-provided payloads, metadata, and routing information across connections. Although the header describes the server's purpose, there is no explicit user-facing warning, confirmation, or disclosure in code comments/logging about sending potentially sensitive agent or system data over the network.
Nearly all user-facing documentation in this file is written in Chinese, with no indication that other languages are available or that the locale is intentionally limited. Under the policy rule, forcing a specific language without user opt-in can be a natural-language policy violation unless the locale constraint is documented and justified.
The natural-language documentation and usage guidance are presented in Chinese, but the file does not indicate that the language is optional or provide an alternative locale. Per the policy, forcing a specific language without user opt-in is a natural-language policy concern.
This markdown file presents all user-facing documentation in a single language, which can violate language/locale policy when no user opt-in or justification is provided. There is no indication that the skill is region-specific or that alternate language support is intentionally constrained.
This file contains many natural-language strings and comments in Chinese, including runtime log messages such as connection, registration, and error notifications. Because the skill does not offer language selection or justify a Chinese-only locale, it may violate the policy against forcing a specific language without user opt-in.
The document sets lang="en", which is a natural-language locale choice embedded in the file. In the provided content, there is no indication that this language setting is user-selectable or specifically justified as a region-specific requirement.
This code file contains natural-language descriptions and user-facing console output in Chinese, which imposes a specific language on users of the example. The policy allows locale constraints only when users are given a choice or the constraint is clearly documented and justified, neither of which appears here.
The lockfile pins @babel/core 7.29.0, and the cited advisory describes an arbitrary file read condition tied to parsing or honoring crafted sourceMappingURL comments. In this package-lock context it is a real supply-chain risk because vulnerable code is present in the dependency tree, though it is dev-only and there is no evidence in this file alone that untrusted attacker-controlled input reaches Babel at runtime.
baseline-browser-mapping 2.10.9 is present and the advisory indicates malformed input can terminate the process, which is a genuine denial-of-service concern in tooling that consumes untrusted data. Here it appears as a transitive dev dependency, so the practical exposure is limited to build/test workflows rather than the ws/uuid production runtime shown at the top of the lockfile.
Dependencies lack version pinning, allowing potential malicious package updates. Consider pinning versions.
"author": "小蒲萄 (Clawd)",
"license": "MIT",
"dependencies": {
"uuid": "^9.0.0",
"ws": "^8.16.0"
},
"devDependencies": {
Dependencies lack version pinning, allowing potential malicious package updates. Consider pinning versions.
"license": "MIT",
"dependencies": {
"uuid": "^9.0.0",
"ws": "^8.16.0"
},
"devDependencies": {
"jest": "^29.7.0",
Dependencies lack version pinning, allowing potential malicious package updates. Consider pinning versions.
"ws": "^8.16.0"
},
"devDependencies": {
"jest": "^29.7.0",
"jest-websocket-mock": "^2.5.0"
},
"engines": {
No suspicious patterns detected.