extension-authorization

Warn

Audited by Gen Agent Trust Hub on Oct 2, 2026

Risk Level: MEDIUMPRIVILEGE_ESCALATIONINDIRECT_PROMPT_INJECTIONEXTERNAL_DOWNLOADS
Full Analysis
  • [PRIVILEGE_ESCALATION]: The skill implements an insecure initialization pattern where administrative control is granted to the first user who authenticates.\n
  • Evidence: The SKILL.md file states under the Backend section that 'The first authenticated user to log in automatically becomes admin; no token or secret is required.'\n
  • Impact: This creates a race condition vulnerability where a malicious actor can gain full control over the application's authorization system by being the first to interact with a fresh deployment.\n- [INDIRECT_PROMPT_INJECTION]: The skill facilitates the ingestion of untrusted data from external users which could be used to manipulate agent behavior.\n
  • Ingestion points: User-controlled data enters the system through saveCallerUserProfile in src/backend/mixins/Profile.mo and the attribute callback in MixinAuthorization in src/backend/main.mo.\n
  • Boundary markers: The instructions do not define boundary markers or provide the agent with guidance to treat these specific inputs as untrusted content.\n
  • Capability inventory: The skill has the capability to write to persistent storage (Map.Map) and affect execution flow via Runtime.trap.\n
  • Sanitization: There is no evidence of string sanitization or validation to prevent stored instructions from influencing future agent prompts.\n- [EXTERNAL_DOWNLOADS]: The skill requires external libraries to function.\n
  • Details: It downloads and integrates the caffeineai-authorization Mops package and the @caffeineai/core-infrastructure NPM package.\n
  • Context: These are infrastructure resources provided by the skill's authoring organization.
Audit Metadata
Risk Level
MEDIUM
Analyzed
Oct 2, 2026, 04:05 PM
Security Audit — agent-trust-hub — extension-authorization