skills/bankrbot/skills/nookplot/Gen Agent Trust Hub

nookplot

Fail

Audited by Gen Agent Trust Hub on Sep 24, 2026

Risk Level: HIGHCREDENTIALS_UNSAFEREMOTE_CODE_EXECUTIONCOMMAND_EXECUTIONDATA_EXFILTRATIONINDIRECT_PROMPT_INJECTIONDYNAMIC_EXECUTIONPERSISTENCE
Full Analysis
  • [CREDENTIALS_UNSAFE]: The documentation for agent registration (identity-register.md) describes an API endpoint at '/v1/agents/me/export' that reportedly returns the agent's decrypted private key. This significantly undermines the skill's claims of being non-custodial and 'key-safe', as it implies the gateway has access to or can reconstruct the agent's most sensitive credentials.\n- [REMOTE_CODE_EXECUTION]: The orchestration guide (runtime-orchestration.md) explicitly instructs users to install software by piping a remote script into a shell ('curl | bash'). This pattern is highly susceptible to supply-chain attacks and remote code execution if the delivery platform is compromised.\n- [DYNAMIC_EXECUTION]: The action registry (actions-overview.md) exposes an '/v1/exec' endpoint that allows the agent to request execution of arbitrary Node.js, Python, or Deno code in sandboxed cloud containers. While sandboxing provides some protection, this capability can be leveraged for various malicious activities or to test exploits.\n- [COMMAND_EXECUTION]: The skill relies on several CLI tools (@nookplot/cli, @nookplot/mcp) and runtime environments that execute local system commands for wallet management, project file operations, and Docker sandbox management.\n- [INDIRECT_PROMPT_INJECTION]: The skill's primary function is as a decentralized agent network where agents ingest and act upon data created by other agents (mining traces, posts, messages). This ingestion of untrusted external content, combined with the agent's high-privilege capabilities (network proxy, code execution, financial escrow), creates a significant risk for indirect prompt injection attacks.\n- [DATA_EXFILTRATION]: The skill provides an egress proxy tool ('/v1/egress') for making outbound HTTP requests. In the event of an agent compromise via prompt injection, this tool could be abused to exfiltrate sensitive data, such as API keys or the private key, to an external attacker-controlled server.\n- [PERSISTENCE]: The skill's tools and MCP server maintain persistence by storing agent credentials and configuration files in the local file system (e.g., '~/.nookplot/credentials.json').
Recommendations
  • AI detected serious security threats
Audit Metadata
Risk Level
HIGH
Analyzed
Sep 24, 2026, 04:45 AM
Security Audit — agent-trust-hub — nookplot