Back to skill

Security audit

Agentic Workflow Automation

Security checks for vulnerabilities and agentic risk

Overview

This skill coherently generates workflow blueprint files, with limited implementation risks around dry-run behavior and CSV export handling.

This appears safe to install for generating blueprint artifacts, but do not rely on its --dry-run option to avoid filesystem changes, avoid writing to sensitive existing paths, and review or sanitize CSV output before opening it in spreadsheet software if the input came from someone else.

Vulnerability Patterns
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (2)

T09 · Insecure Skill Coding Practices

Warning
Location
scripts/generate_workflow_blueprint.py:55
Finding

Spreadsheet Formula Injection in CSV Output

Content
View full analysis
Remediation
View remediation
str: text = str(value) if text.startswith(("=", "+", "-", "@")): return "'" + text return text ``` Apply the function when normalizing or immediately before writing CSV rows: ```python safe_steps = [ { "order": step["order"], "name": sanitize_csv_cell(step["name"]), "type": sanitize_csv_cell(step["type"]), "on_failure": sanitize_csv_cell(step["on_failure"]), } for step in result["details"]["steps"] ] writer.writerows(safe_steps) ``` Additional hardening measures: 1. Apply formula neutralization only to CSV output so that JSON and Markdown retain their original values. 2. Document that imported workflow fields are untrusted. 3. Add tests covering values beginning with each formula marker. 4. Test the resulting CSV files with the spreadsheet applications expected in the deployment environment. 5. Do not rely on CSV quoting alone, because quoting does not reliably disable spreadsheet formula interpretation. ]]>

T09 · Insecure Skill Coding Practices

Note
Location
scripts/generate_workflow_blueprint.py:105
Finding

Dry-Run Mode Performs Filesystem Side Effects

Content
View full analysis
None: output_path.parent.mkdir(parents=True, exist_ok=True) if fmt == "json": output_path.write_text(json.dumps(result, indent=2), encoding="utf-8") return if fmt == "md": details = result["details"] lines = [ f"# {result['summary']}", "", f"- status: {result['status']}", f"- workflow_name: {details['workflow_name']}", f"- trigger: {details['trigger']}", "", "## Steps", ] for step in details["steps"]: lines.append(f"- {step['order']}. {step['name']} ({step['type']})") output_path.write_text("\n".join(lines) + "\n", encoding="utf-8") return with output_path.open("w", newline="", encoding="utf-8") as handle: writer = csv.DictWriter(handle, fieldnames=["order", "name", "type", "on_failure"]) writer.writeheader() writer.writerows(result["details"]["steps"]) ``` ### Technical Analysis The `--dry-run` value is included only as metadata in the generated result. It is never used to prevent `render()` from executing. Consequently, dry-run mode has the same output-related side effects as normal mode: - Missing parent directories are created. - A new output artifact is created. - ...[truncated 1429 chars]
Remediation
View remediation
Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
Findings (3)

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
93% confidence
Finding

The skill instructs use of a bundled Python script and a reference file, which implies file read and file write capabilities, but it does not declare any explicit tool scope such as permissions or allowed-tools. This creates an authorization ambiguity where an agent or runtime may grant broader filesystem access than intended, increasing the risk of unintended file access or artifact creation in surrounding directories.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The script advertises a --dry-run mode, but main() always calls render(result, Path(args.output), args.format), and render() always creates parent directories and writes the output file. This can mislead users or calling agents into believing no side effects will occur, causing unintended file creation or overwrite in automation contexts where dry-run is relied on for safety checks.

Content

No source excerpt is available for this finding.

Vague Triggers

Low
Category
Not specified by scanner
Confidence
91% confidence
Finding

This markdown file asks for a trigger field but does not define acceptable trigger phrases, scope, or exclusion conditions. That ambiguity can lead to overly broad or inconsistent workflow activations, especially in automation tooling.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.