extension-authorization
Warn
Audited by Gen Agent Trust Hub on Oct 2, 2026
Risk Level: MEDIUMPRIVILEGE_ESCALATIONINDIRECT_PROMPT_INJECTIONEXTERNAL_DOWNLOADS
Full Analysis
- [PRIVILEGE_ESCALATION]: The skill implements an insecure initialization pattern where administrative control is granted to the first user who authenticates.\n
- Evidence: The SKILL.md file states under the Backend section that 'The first authenticated user to log in automatically becomes admin; no token or secret is required.'\n
- Impact: This creates a race condition vulnerability where a malicious actor can gain full control over the application's authorization system by being the first to interact with a fresh deployment.\n- [INDIRECT_PROMPT_INJECTION]: The skill facilitates the ingestion of untrusted data from external users which could be used to manipulate agent behavior.\n
- Ingestion points: User-controlled data enters the system through
saveCallerUserProfileinsrc/backend/mixins/Profile.moand the attribute callback inMixinAuthorizationinsrc/backend/main.mo.\n - Boundary markers: The instructions do not define boundary markers or provide the agent with guidance to treat these specific inputs as untrusted content.\n
- Capability inventory: The skill has the capability to write to persistent storage (
Map.Map) and affect execution flow viaRuntime.trap.\n - Sanitization: There is no evidence of string sanitization or validation to prevent stored instructions from influencing future agent prompts.\n- [EXTERNAL_DOWNLOADS]: The skill requires external libraries to function.\n
- Details: It downloads and integrates the
caffeineai-authorizationMops package and the@caffeineai/core-infrastructureNPM package.\n - Context: These are infrastructure resources provided by the skill's authoring organization.
Audit Metadata