Back to skill

Security audit

Miro Web SDK Reference

Security checks for vulnerabilities and agentic risk

Overview

This is a documentation-only Miro SDK skill with purpose-aligned examples, though users should be careful with copied examples that delete board content, export board data, or send logs to a backend.

Install this as an SDK reference, not as automatically safe production code. When using its examples, pin dependency versions, request only needed Miro scopes, confirm destructive board actions, avoid bulk deletion unless intentional, and sanitize or minimize any board, user, or error data sent to a backend.

Vulnerability Patterns
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
Findings (2)

T09 · Insecure Skill Coding Practices

Warning
Location
references/best-practices.md:163
Finding

Sensitive User Data and Diagnostic Information May Be Transmitted Without Adequate Safeguards

Content
View full analysis
{ // Send to monitoring service fetch('/api/errors', { method: 'POST', body: JSON.stringify({ message: event.message, stack: event.error?.stack, timestamp: new Date() }) }); }); } ``` From `references/error-handling.md:369-390`: ```typescript class ErrorLogger { private logs: any[] = []; log(error: Error, context?: Record) { this.logs.push({ message: error.message, code: error.code, stack: error.stack, context, timestamp: new Date() }); // Send to server this.flushIfNeeded(); } private async flushIfNeeded() { if (this.logs.length > 10) { const logs = this.logs.splice(0, 10); await fetch('/api/logs', { method: 'POST', body: JSON.stringify(logs) }).catch(console.error); } } } ``` ### Technical Analysis These examples serialize and transmit arbitrary user data, exception messages, stack traces, and unrestricted context objects to backend endpoints. They do not demonstrate: - A strict allowlist for transmitted fields. - Redaction of access tokens, email add ...[truncated 2563 chars]
Remediation
View remediation

T08 · Insecure Dependencies

Note
Location
SKILL.md:14
Finding

Unpinned npm Installation and Scaffolding Commands Create Supply-Chain Exposure

Content
View full analysis
Remediation
View remediation
my-plugin npm install --save-exact @mirohq/miro-webplugin@ npx vercel@ ``` 2. Commit `package-lock.json` and use `npm ci` for existing projects and automated builds. 3. Prefer project-local tools invoked through package scripts or pinned `npx` commands instead of `npm install -g`. 4. Document the expected npm registry and reject unexpected registry overrides in trusted build environments. 5. Review package provenance, publisher identity, integrity metadata, lifecycle scripts, and transitive dependencies before updating. 6. Enable dependency auditing and automated update review, but do not merge dependency updates without validation. 7. Run installation and build steps in an isolated, non-privileged container with only the minimum required secrets. 8. Do not expose production deployment credentials during dependency installation. 9. Consider using `npm install --ignore-scripts` during inspection where lifecycle scripts are not required, followed by an explicit review of any necessary scripts. 10. Pin the Docker base image by digest to improve build reproducibility in addition to pinning npm dependencies. ]]>
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (12)

Credential Access

High
Category
Privilege Escalation
Confidence
70% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · references/authentication.md (reported line 102)May include surrounding context.

text
miro.board.getInfo()
  ↓
SDK gets access token
  ↓
API request with token
  ↓

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

This markdown file applies to SQP-2, and it explicitly advertises update and delete operations on board items, including 'Delete items,' without any caution about modifying or removing user data. The document presents these capabilities as routine features but does not warn that plugin actions can change or delete content on a user's Miro board.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
87% confidence
Finding

The file states that the plugin can automatically access the current user and requests scopes such as 'board:write' and 'identity:read,' but it does not disclose the privacy implications of reading user identity or modifying board data. For markdown files, SQP-2 requires warnings when behavior could affect user data or privacy.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

This markdown file includes a 'Secure Storage' example that sends user data to '/api/user-data' and frames server-side storage as a best practice, but it does not warn users or developers about privacy implications, consent, or what data may be transmitted. For markdown files, SQP-2 applies when descriptions omit warnings about behaviors that could affect user data or privacy.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
97% confidence
Finding

The error-tracking example automatically transmits error messages and stack traces to a backend, which can include sensitive data such as tokens, personal data, URLs, or internal implementation details. In SDK best-practices documentation, this is risky because developers may copy the pattern directly without adding redaction, consent, or telemetry controls.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

This markdown reference includes direct item deletion and batch deletion examples, including deleting all board items, but does not warn readers about the destructive nature of these operations or suggest confirmation/undo patterns. In documentation, omission of such warnings can lead to accidental data loss when users copy these examples into skills.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

Medium
Category
Not specified by scanner
Confidence
90% confidence
Finding

The example ErrorLogger batches error details including message, code, stack, timestamp, and arbitrary context, then transmits them to '/api/logs' without any guidance on minimization, redaction, consent, or transport/security controls. In an SDK reference document, this normalizes remote telemetry that can leak sensitive board data, user identifiers, or internal application details if developers copy the pattern directly.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The documentation shows automatic transmission of collected error logs to a server once a threshold is reached, but provides no user-facing warning or disclosure. This creates a privacy and transparency issue because developers may adopt the snippet as-is, causing background export of potentially sensitive diagnostic data without informing users.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
88% confidence
Finding

This markdown file includes an example that reads all board items and downloads their content and positions to a JSON file. The surrounding description does not warn that the operation exports potentially sensitive board data, which fits the markdown-specific missing user warnings category.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The keyboard shortcut example binds the Delete key to remove all selected items via item.delete(), but the markdown description provides no caution that this is destructive and may be irreversible. For markdown files, destructive behavior should be accompanied by a clear warning to users.

Content

No source excerpt is available for this finding.

Cloud Storage Exfiltration

Medium
Category
Data Exfiltration
Confidence
60% confidence
Finding

Data is uploaded to cloud storage (S3 / GCS / Azure Blob). This may be a legitimate backup or exfiltration to an external bucket. Manual review is recommended.

Content

Scanner excerpt · references/setup-installation.md (reported line 176)May include surrounding context.

bash
npm run build
aws s3 sync dist/ s3://my-bucket/

Installing in Production

Missing User Warnings

Low
Category
Not specified by scanner
Confidence
77% confidence
Finding

The examples expose owner and current-user fields such as email addresses and names, but the markdown does not mention that these values may be sensitive personal data. For documentation that demonstrates reading user metadata, a short privacy warning helps prevent misuse or unnecessary collection/logging.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.