stacktree-publish
Fail
Audited by Snyk on Aug 20, 2026
Risk Level: HIGH
Full Analysis
HIGH W007: Insecure credential handling detected in skill instructions.
- Insecure credential handling detected (high risk: 1.00). The skill instructs embedding secrets directly (e.g., STACKTREE_API_KEY and passing --password on the command line, with an explicit example
--password hunter2) and asks the agent to prompt for/set API keys, which would require the LLM to emit secret values verbatim in commands or responses.
MEDIUM W011: Third-party content exposure detected (indirect prompt injection risk).
- Third-party content exposure detected (medium risk: 0.30). In
scripts/publish.sh(used by the required workflows), the agent-runtime ingests outsider-provided HTML/strings from conversation intocat > "$TMP"and uploads them to Stacktree viacurltohttps://api.stacktr.ee/sitesor.../sites/:idfor publishing.
MEDIUM W012: Unverifiable external dependency detected (runtime URL that controls agent).
- Potentially malicious external URL detected (high risk: 0.90). The skill makes runtime HTTP calls to endpoints that return actionable instructions the agent must follow (e.g., POST https://api.stacktr.ee/pay/sessions returns a qr/poll flow, and POST https://api.stacktr.ee/custom-domains returns DNS "instructions"; the agent may also POST to https://agents.stacktr.ee/api/publish and https://api.stacktr.ee/provision), so external responses can directly control the agent's next actions.
MEDIUM W009: Direct money access capability detected (payment gateways, crypto, banking).
- Direct money access detected (high risk: 1.00). The skill explicitly describes autonomous payment flows: POSTing to publish/provision endpoints that return 402 and must be paid (mentions paying $0.50 or $1), agent-signed crypto payments over x402 (USDC on Base or Solana) or MPP (USDC.e on Tempo), and a pay-session flow that results in a Stripe card payment via QR. These are concrete, specific payment mechanisms (crypto signing and a Stripe gateway) enabling an agent to move money or sign transactions; therefore it grants Direct Financial Execution Authority.
Issues (4)
W007
HIGHInsecure credential handling detected in skill instructions.
W011
MEDIUMThird-party content exposure detected (indirect prompt injection risk).
W012
MEDIUMUnverifiable external dependency detected (runtime URL that controls agent).
W009
MEDIUMDirect money access capability detected (payment gateways, crypto, banking).
Audit Metadata