Back to skill

Security audit

Verified Business Memory

Security checks for vulnerabilities and agentic risk

Overview

This skill is a disclosed BlueColumn integration for storing and recalling business facts, with no hidden code, local persistence, or unrelated authority found.

Install only if you are comfortable using BlueColumn as a third-party store for business facts. Use a least-privilege API key if available, avoid sending secrets, customer personal data, or confidential internal rationale, and verify recalled facts before using them in customer-facing answers.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Findings (4)

External Transmission

Medium
Category
Data Exfiltration
Confidence
85% confidence
Finding

The documented endpoint points to an external service domain and normalizes sending data and credentials to that service. Even though HTTPS is used, the security concern is not transport secrecy alone but the transfer of potentially sensitive internal data and use of a live API key with a third party. In this context, the skill makes external disclosure core to its workflow, so this is a genuine exposure point rather than a harmless reference.

Content

Scanner excerpt · SKILL.md (reported line 19)May include surrounding context.

Every fact carries a date and a source, so it can be verified later.

bash
curl -X POST https://api.bluecolumn.ai/remember \
  -H "Authorization: Bearer $BLUECOLUMN_API_KEY" \
  -H "Content-Type: application/json" \
  -d '{

External Transmission

Medium
Category
Data Exfiltration
Confidence
85% confidence
Finding

The documented endpoint points to an external service domain and normalizes sending data and credentials to that service. Even though HTTPS is used, the security concern is not transport secrecy alone but the transfer of potentially sensitive internal data and use of a live API key with a third party. In this context, the skill makes external disclosure core to its workflow, so this is a genuine exposure point rather than a harmless reference.

Content

Scanner excerpt · SKILL.md (reported line 19)May include surrounding context.

Every fact carries a date and a source, so it can be verified later.

bash
curl -X POST https://api.bluecolumn.ai/remember \
  -H "Authorization: Bearer $BLUECOLUMN_API_KEY" \
  -H "Content-Type: application/json" \
  -d '{

External Transmission

Medium
Category
Data Exfiltration
Confidence
83% confidence
Finding

The /recall request sends business queries to an external service and may expose customer-support context, internal policy questions, or proprietary operational details. Although querying a remote memory service is expected behavior, it still represents external transmission of potentially sensitive business context and dependency on a third-party system for customer-facing answers. That dependency can amplify impact if the service is compromised or if stored content is inaccurate.

Content

Scanner excerpt · SKILL.md (reported line 33)May include surrounding context.

Customer-facing agents recall before answering, so they quote current facts.

bash
curl -X POST https://api.bluecolumn.ai/recall \
  -H "Authorization: Bearer $BLUECOLUMN_API_KEY" \
  -H "Content-Type: application/json" \
  -d '{"q": "What is the current price for a residential deep clean and the current cancellation policy?"}'

External Transmission

Medium
Category
Data Exfiltration
Confidence
88% confidence
Finding

The conflict-reporting flow sends discrepancy notes, including internal corrections and source locations, to an external API. Such notes can reveal unpublished pricing changes, internal policy mismatches, or operational issues that may be sensitive from a business or legal perspective. Because the skill encourages logging these discrepancies immediately, it increases the chance that sensitive internal observations are exported without review.

Content

Scanner excerpt · SKILL.md (reported line 42)May include surrounding context.

Flag a conflict the moment you see one

bash
curl -X POST https://api.bluecolumn.ai/note \
  -H "Authorization: Bearer $BLUECOLUMN_API_KEY" \
  -H "Content-Type: application/json" \
  -d '{"text": "CONFLICT: website still lists deep clean at $169; verified price is $189 since 09-01. Source of conflict: /pricing page.", "tags": ["verified", "conflict", "pricing"]}'

Static analysis

No suspicious patterns detected.