Back to skill

Security audit

agent-resume

Security checks for vulnerabilities and agentic risk

Overview

This is a disclosed third-party checkpointing skill, with the main caution that saved agent summaries may contain sensitive work details.

Use this only for checkpoint summaries you are allowed to store with BlueColumn. Redact secrets, credentials, customer data, private URLs, security details, and internal ticket information unless your organization has approved that storage.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Findings (5)

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
97% confidence
Finding

The skill explicitly instructs operators to send detailed agent checkpoints to a third-party API, including completed work, unfinished work, decisions, blockers, and next steps, with no warning to exclude secrets, client data, internal URLs, or sensitive operational details. In this context, the example payload already contains project-specific implementation choices and client IT ticket information, demonstrating a realistic path for unauthorized external disclosure of confidential data.

Content

No source excerpt is available for this finding.

External Transmission

Medium
Category
Data Exfiltration
Confidence
91% confidence
Finding

The referenced external domain itself is not inherently malicious, but embedding a third-party API endpoint in a skill that persists agent state materially increases data exposure risk. The danger comes from normalizing outbound transmission of potentially sensitive session context without user safeguards or disclosure controls.

Content

Scanner excerpt · SKILL.md (reported line 19)May include surrounding context.

Before any restart, model swap, or context reset, store the state that matters.

bash
curl -X POST https://api.bluecolumn.ai/remember \
  -H "Authorization: Bearer $BLUECOLUMN_API_KEY" \
  -H "Content-Type: application/json" \
  -d '{

External Transmission

Medium
Category
Data Exfiltration
Confidence
91% confidence
Finding

The referenced external domain itself is not inherently malicious, but embedding a third-party API endpoint in a skill that persists agent state materially increases data exposure risk. The danger comes from normalizing outbound transmission of potentially sensitive session context without user safeguards or disclosure controls.

Content

Scanner excerpt · SKILL.md (reported line 19)May include surrounding context.

Before any restart, model swap, or context reset, store the state that matters.

bash
curl -X POST https://api.bluecolumn.ai/remember \
  -H "Authorization: Bearer $BLUECOLUMN_API_KEY" \
  -H "Content-Type: application/json" \
  -d '{

External Transmission

Medium
Category
Data Exfiltration
Confidence
88% confidence
Finding

The recall operation queries the external service for prior agent checkpoints, reinforcing a workflow where sensitive operational memory is stored outside the primary environment. If prior checkpoints contained confidential data, this design expands the persistence and retrieval surface for that data beyond the user's local system.

Content

Scanner excerpt · SKILL.md (reported line 33)May include surrounding context.

On a fresh session, pull the latest checkpoint first thing.

bash
curl -X POST https://api.bluecolumn.ai/recall \
  -H "Authorization: Bearer $BLUECOLUMN_API_KEY" \
  -H "Content-Type: application/json" \
  -d '{"q": "What is the latest agent checkpoint and what was in progress, decided, blocked, and next?"}'

External Transmission

Medium
Category
Data Exfiltration
Confidence
93% confidence
Finding

The note endpoint encourages frequent mid-run uploads of implementation decisions to an external API, increasing the volume and granularity of data leaving the environment. Repeated small disclosures can cumulatively reveal architecture, security decisions, tenant design, and operational practices useful to an attacker or inappropriate for third-party storage.

Content

Scanner excerpt · SKILL.md (reported line 44)May include surrounding context.

Capture a decision the moment it happens, so it survives the next wipe.

bash
curl -X POST https://api.bluecolumn.ai/note \
  -H "Authorization: Bearer $BLUECOLUMN_API_KEY" \
  -H "Content-Type: application/json" \
  -d '{"text": "Decision: retry queue uses Redis Streams, consumer group per tenant. Do not use Postgres SKIP LOCKED.", "tags": ["agent-resume", "decision"]}'

Static analysis

No suspicious patterns detected.