Back to skill

Security audit

Release Final4

Security checks for vulnerabilities and agentic risk

Overview

This is a disclosed Theta EdgeCloud integration with real billing and resource-management powers that are scoped to Theta APIs and gated by confirmation.

Install only if you intend to let an agent operate Theta EdgeCloud resources. Use least-privilege Theta keys, provider quotas, dry-run for rehearsals, and require explicit approval for each billable or destructive action; treat prompts, uploaded files, character messages, outputs, and presigned URLs as private.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
Findings (18)

Tp4

High
Category
MCP Tool Poisoning
Confidence
95% confidence
Finding

The description claims a wide-ranging Theta EdgeCloud skill covering AI inference, GPU nodes, RAG agents, service discovery, approved resource management, and cost verification across multiple workflow types. The supplied code does something much narrower: it talks only to api.thetavideoapi.com using Theta Video service-account headers, and exposes video/stream/ingestor operations. While the confirmation-gated create/select behavior partially aligns with the 'approved resources with confirmation gates' claim, the primary purpose and capabilities are materially different and significantly narrower than declared. Therefore this is a description-to-behavior mismatch.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
95% confidence
Finding

The declared description presents a broad Theta EdgeCloud on-demand AI/GPU and workflow management skill, including service discovery, inference, approval-gated resource management, and cost checks. This code chunk instead targets a specific AI Characters API endpoint and performs CRUD and session messaging operations for game characters. While the confirmation gate on non-GET requests aligns with part of the description, the primary behavior here is character/session management on a separate game-scoped API, which is not accurately represented by the declared purpose. Therefore this is a material description/behavior mismatch.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
97% confidence
Finding

The declared description is about interacting with Theta EdgeCloud services and resource management workflows. The actual code chunk does not perform cloud discovery, inference, resource management, confirmation gating, or cost verification. Instead, it is a generic utility for sanitizing sensitive data in structured objects. That is a materially different primary purpose, so this is a clear description-behavior mismatch.

Content

No source excerpt is available for this finding.

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 47)May include surrounding context.

md
- Packaging: one unminified bundle, `dist/index.js`, built from the included

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 56)May include surrounding context.

md
- Packaging: one unminified bundle, `dist/index.js`, built from the included

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 55)May include surrounding context.

md
Read `references/capabilities.md` for command families and coverage limits.

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 153)May include surrounding context.

md
Read `references/capabilities.md` for command families and coverage limits.

Env Variable Harvesting

High
Category
Data Exfiltration
Confidence
60% confidence
Finding

Code enumerates, copies, or searches environment variables for secrets. Bulk environment access can collect credentials unrelated to the skill's stated purpose.

Content

Scanner excerpt · tests/unit/astra-regression.test.mjs (reported line 107)May include surrounding context.

js
assert.equal(out.body[0].auth_password, '[redacted]');
    }, reply);
    assert.equal(f.error, undefined, String(f.error));
  } finally { for (const k of Object.keys(process.env)) if (!(k in prior)) delete process.env[k]; Object.assign(process.env, prior); }
});

test('C1: a changing ctx.env getter cannot route operator Basic auth to another tenant', async () => {

Env Variable Harvesting

High
Category
Data Exfiltration
Confidence
60% confidence
Finding

Code enumerates, copies, or searches environment variables for secrets. Bulk environment access can collect credentials unrelated to the skill's stated purpose.

Content

Scanner excerpt · tests/unit/astra-regression.test.mjs (reported line 120)May include surrounding context.

js
assert.equal(out.body[0].auth_password, '[redacted]');
    }, reply);
    assert.equal(f.error, undefined, String(f.error));
  } finally { for (const k of Object.keys(process.env)) if (!(k in prior)) delete process.env[k]; Object.assign(process.env, prior); }
});

test('C1: a changing ctx.env getter cannot route operator Basic auth to another tenant', async () => {

Env Variable Harvesting

High
Category
Data Exfiltration
Confidence
60% confidence
Finding

Code enumerates, copies, or searches environment variables for secrets. Bulk environment access can collect credentials unrelated to the skill's stated purpose.

Content

Scanner excerpt · tests/unit/astra-regression.test.mjs (reported line 136)May include surrounding context.

js
assert.equal(out.body[0].auth_password, '[redacted]');
    }, reply);
    assert.equal(f.error, undefined, String(f.error));
  } finally { for (const k of Object.keys(process.env)) if (!(k in prior)) delete process.env[k]; Object.assign(process.env, prior); }
});

test('C1: a changing ctx.env getter cannot route operator Basic auth to another tenant', async () => {

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
90% confidence
Finding

The skill declares substantial network and credential-handling behavior but does not provide an explicit tool-scope/permission declaration in the skill metadata. That weakens reviewability and increases the risk that an agent or reviewer underestimates the skill's access to environment secrets and outbound HTTPS destinations, especially given the broad operational surface described in the file.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
90% confidence
Finding

The file states that GPU deployment creation is paid, start resumes billing, and delete is permanent. Although these effects are mentioned inline, there is no clear warning or cautionary note highlighting the user-data/system-impact risk of irreversible deletion and unexpected charges in the skill description.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
84% confidence
Finding

The markdown lists create, update, delete, and session mutation operations and notes confirm:true is required outside dry-run, but it does not present a user-facing warning that these operations change or remove remote resources. For markdown files, state-changing behaviors that can affect user data should be clearly warned about, not only embedded in operational details.

Content

No source excerpt is available for this finding.

Autonomous Decision Making

Medium
Category
Excessive Agency
Confidence
75% confidence
Finding

Skill enables autonomous high-impact decisions without human-in-the-loop verification. Critical operations (destructive commands, financial transactions, data deletion) should require explicit user confirmation.

Content

Scanner excerpt · src/commands/deployments.ts (reported line 193)May include surrounding context.

ts
});
    }

    // PAID create + delete: refuse before any request (including the balance read) without approval.
    assertApproved(cfg, opts.confirm, 'theta.deployments.validateDisposable');
    let created: unknown;
    let readiness: unknown;

Intent-Code Divergence

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The comment block presents the module as a read-only facade that cannot send prompts, spend credits, or modify remote resources. However, L74-L78 export executeThetaRuntimeCommand and related runtime command metadata, and the comment itself acknowledges that this executor runs every command, including mutations and high-cost operations, creating an active contradiction in the documented intent of the module's exposed capabilities.

Content

No source excerpt is available for this finding.

External Transmission

Medium
Category
Data Exfiltration
Confidence
50% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · tests/contracts/video.contract.test.ts (reported line 7)May include surrounding context.

ts
import { executeThetaRuntimeCommand as run } from '../../dist/index.js';

test('video inspection uses service-account auth and fixed Theta host', async () => {
 const prior=globalThis.fetch;globalThis.fetch=async(url,init)=>{assert.equal(String(url),'https://api.thetavideoapi.com/video/test-video');assert.equal(new Headers(init?.headers).get('x-tva-sa-id'),'test-account');return new Response('{}');};
 try{await run({command:'theta.video.get',videoId:'test-video'},{env:{THETA_VIDEO_SA_ID:'test-account',THETA_VIDEO_SA_SECRET:'test-secret'}});}finally{globalThis.fetch=prior;}
});

External Transmission

Medium
Category
Data Exfiltration
Confidence
50% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · tests/unit/security.test.mjs (reported line 49)May include surrounding context.

js
import { executeThetaRuntimeCommand as run } from '../../dist/index.js';

test('video inspection uses service-account auth and fixed Theta host', async () => {
 const prior=globalThis.fetch;globalThis.fetch=async(url,init)=>{assert.equal(String(url),'https://api.thetavideoapi.com/video/test-video');assert.equal(new Headers(init?.headers).get('x-tva-sa-id'),'test-account');return new Response('{}');};
 try{await run({command:'theta.video.get',videoId:'test-video'},{env:{THETA_VIDEO_SA_ID:'test-account',THETA_VIDEO_SA_SECRET:'test-secret'}});}finally{globalThis.fetch=prior;}
});

Missing User Warnings

Low
Category
Not specified by scanner
Confidence
83% confidence
Finding

This markdown file explains that the runtime calls the hosted MCP endpoint with a project key via x-api-key / THETA_EC_API_KEY, but it does not include any caution about protecting or not exposing those credentials. Because markdown files should warn about behaviors affecting privacy or system integrity, mentioning credential use without any user-facing warning is a minor omission.

Content

No source excerpt is available for this finding.

Static analysis

Detected: suspicious.env_credential_access, suspicious.exposed_secret_literal

Environment variable access combined with network send.

Critical
Code
suspicious.env_credential_access
Location
dist/index.js:2

File appears to expose a hardcoded API secret or token.

Critical
Code
suspicious.exposed_secret_literal
Location
tests/unit/deployments.test.mjs:86

File appears to expose a hardcoded API secret or token.

Critical
Code
suspicious.exposed_secret_literal
Location
tests/unit/runtime-handlers.test.mjs:256

File appears to expose a hardcoded API secret or token.

Critical
Code
suspicious.exposed_secret_literal
Location
tests/unit/v0129-features.test.mjs:7