Back to skill

Security audit

Baby Sleep & Cry Memory

Security checks for vulnerabilities and agentic risk

Overview

The skill is coherent and not deceptive, but it directs users to send sensitive nursery audio and infant sleep history to an external indexing service without privacy, consent, retention, or deletion guidance.

Review this carefully before installing. Use it only if the parent or guardian understands that nursery recordings, child sleep history, and related notes are sent to BlueColumn and indexed for later recall. Avoid real names and unnecessary medical or family details, use controlled audio URLs, and confirm BlueColumn's retention, deletion, and access-control practices before uploading real data.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Findings (5)

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The skill explicitly encourages sending overnight nursery audio and infant sleep logs, including timestamps, feeding details, illness/training notes, and a child's name/age, to a third-party API without any privacy warning, consent guidance, or data-handling disclosure. This is sensitive family and child data, and the context makes the risk more serious because it involves recordings from a private bedroom/nursery and behavioral/health-adjacent information about an infant.

Content

No source excerpt is available for this finding.

External Transmission

Medium
Category
Data Exfiltration
Confidence
96% confidence
Finding

This endpoint transmits overnight nursery audio and structured infant sleep data to an external API, creating a direct exfiltration path for highly sensitive household recordings and child-related data. In this skill's context, the transmission is more dangerous than generic external API use because the content may include voices of minors, caregivers, and intimate in-home activity from a bedroom environment.

Content

Scanner excerpt · SKILL.md (reported line 19)May include surrounding context.

Send the monitor recording; BlueColumn transcribes and indexes the events as structured sleep-log entries.

bash
curl -X POST https://api.bluecolumn.ai/remember \
  -H "Authorization: Bearer $BLUECOLUMN_API_KEY" \
  -H "Content-Type: application/json" \
  -d '{

External Transmission

Medium
Category
Data Exfiltration
Confidence
96% confidence
Finding

This endpoint transmits overnight nursery audio and structured infant sleep data to an external API, creating a direct exfiltration path for highly sensitive household recordings and child-related data. In this skill's context, the transmission is more dangerous than generic external API use because the content may include voices of minors, caregivers, and intimate in-home activity from a bedroom environment.

Content

Scanner excerpt · SKILL.md (reported line 19)May include surrounding context.

Send the monitor recording; BlueColumn transcribes and indexes the events as structured sleep-log entries.

bash
curl -X POST https://api.bluecolumn.ai/remember \
  -H "Authorization: Bearer $BLUECOLUMN_API_KEY" \
  -H "Content-Type: application/json" \
  -d '{

External Transmission

Medium
Category
Data Exfiltration
Confidence
88% confidence
Finding

The recall request sends a child-specific query to an external service that reveals historical sleep and caregiving patterns across multiple nights. While less sensitive than raw audio, it still exposes private infant behavioral data and family routines to a third party, which is significant in this context because it concerns a minor and longitudinal household data.

Content

Scanner excerpt · SKILL.md (reported line 34)May include surrounding context.

Ask what changed, not just what happened.

bash
curl -X POST https://api.bluecolumn.ai/recall \
  -H "Authorization: Bearer $BLUECOLUMN_API_KEY" \
  -H "Content-Type: application/json" \
  -d '{"q": "For Theo over the last 7 nights, has the 03:50 night waking gotten earlier or longer, and what settling method followed each one?"}'

External Transmission

Medium
Category
Data Exfiltration
Confidence
92% confidence
Finding

The note endpoint sends one-off observations such as illness, travel, and sleep-training interventions to an external API. These details can reveal sensitive health-adjacent and family-behavior information about an infant, and the risk is elevated because the skill encourages longitudinal tracking tied to a specific child.

Content

Scanner excerpt · SKILL.md (reported line 45)May include surrounding context.

Capture a single detail the audio cannot show — illness, travel, a schedule change.

bash
curl -X POST https://api.bluecolumn.ai/note \
  -H "Authorization: Bearer $BLUECOLUMN_API_KEY" \
  -H "Content-Type: application/json" \
  -d '{"text": "Theo: started sleep training 10-04 (extinction, 5m check-ins). Expect short-term regression; do not flag as a new pattern until 3 nights of data.", "tags": ["sleep-log", "theo-5mo", "training"]}'

Static analysis

No suspicious patterns detected.