Back to skill

Security audit

client-flow

Security checks for vulnerabilities and agentic risk

Overview

This skill automates disclosed client-onboarding work across files, email, calendar, tasks, reminders, and a client registry, with risks that are expected for that purpose.

Before installing, confirm where client folders and registries will be stored, review recipients and message bodies before sending email, and be mindful that client contact details, budgets, project status, reminders, and templates may persist in workspace memory or local/cloud files.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
Findings (5)

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

The invocation phrases are broad enough to capture common project-management or status requests, which can cause the skill to activate in contexts where the user did not intend onboarding automation. Because the skill performs side-effecting actions across storage, email, calendar, and task tools, overbroad triggering increases the risk of unintended writes, messages, and scheduling operations.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The skill creates folders and saves project documents to local or cloud storage without an explicit user-facing notice that persistent file writes will occur. In practice, this can expose sensitive client information to unintended locations, shared drives, synced folders, or misconfigured local paths, especially when the base path or cloud destination is only implied.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The skill drafts or sends email using extracted client contact information without clearly warning that personal data will be transmitted to an external email system. This creates privacy and misdelivery risks if the extracted address is wrong, if the user did not expect outbound communication, or if the email is sent automatically with incomplete review.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The skill stores a client registry, business configuration, and contact/project metadata in workspace memory or files without clearly disclosing persistent retention. This can accumulate sensitive business and personal information over time, increasing exposure from unauthorized access, cross-task reuse, oversharing in later prompts, or insecure local/cloud storage.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The manifest describes onboarding across email, calendar, file storage, task management, and client/project tracking tools. At L235-L236, the documentation says users can configure onboarding templates to also perform GitHub repo setup and Slack channel creation, adding engineering collaboration capabilities not declared in the manifest's stated purpose or tool scope.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.