Back to skill

Security audit

Podcast Mention Memory

Security checks for vulnerabilities and agentic risk

Overview

This skill is a straightforward BlueColumn integration for indexing and recalling podcast mentions, with third-party data transfer visible and aligned to its stated purpose.

Before installing, confirm that sending podcast audio URLs, transcripts, client names, sentiment judgments, and analyst notes to BlueColumn is allowed by your privacy and client-data policies. Avoid regulated or confidential material unless you have reviewed BlueColumn retention and deletion controls.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Findings (5)

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

The skill explicitly instructs users to send audio URLs, transcripts, mention metadata, sentiment, and analyst notes to BlueColumn for persistent storage and later recall, but it does not clearly warn users in the skill description or usage guidance that this data leaves the local environment and is retained by a third-party service. This creates a real privacy and data-governance risk because users may transmit sensitive media, reputational intelligence, and internal analyst annotations without informed consent or policy review.

Content

No source excerpt is available for this finding.

External Transmission

Medium
Category
Data Exfiltration
Confidence
94% confidence
Finding

This endpoint sends an external request to BlueColumn's /remember API with an audio URL and structured text containing brand mentions, speaker attribution, timestamps, and sentiment. In context this is the core function of the skill, but it is still a genuine security/privacy concern because potentially sensitive media-derived intelligence is exported to a third-party service for storage and search.

Content

Scanner excerpt · SKILL.md (reported line 30)May include surrounding context.

precise later.

bash
curl -X POST https://api.bluecolumn.ai/remember \
  -H "Authorization: Bearer $BLUECOLUMN_API_KEY" \
  -H "Content-Type: application/json" \
  -d '{

External Transmission

Medium
Category
Data Exfiltration
Confidence
94% confidence
Finding

This endpoint sends an external request to BlueColumn's /remember API with an audio URL and structured text containing brand mentions, speaker attribution, timestamps, and sentiment. In context this is the core function of the skill, but it is still a genuine security/privacy concern because potentially sensitive media-derived intelligence is exported to a third-party service for storage and search.

Content

Scanner excerpt · SKILL.md (reported line 30)May include surrounding context.

precise later.

bash
curl -X POST https://api.bluecolumn.ai/remember \
  -H "Authorization: Bearer $BLUECOLUMN_API_KEY" \
  -H "Content-Type: application/json" \
  -d '{

External Transmission

Medium
Category
Data Exfiltration
Confidence
90% confidence
Finding

The /recall request sends a natural-language query about indexed mentions to an external service, potentially exposing internal monitoring interests, client names, campaign focus, and investigative scope. While expected for the product's functionality, it still poses a confidentiality risk because queries themselves can reveal sensitive business intent even when no raw audio is included.

Content

Scanner excerpt · SKILL.md (reported line 45)May include surrounding context.

Ask in plain English; the answer cites show, episode, timestamp, and framing.

bash
curl -X POST https://api.bluecolumn.ai/recall \
  -H "Authorization: Bearer $BLUECOLUMN_API_KEY" \
  -H "Content-Type: application/json" \
  -d '{"q": "Every mention of Acme on finance or startup podcasts in Q3 2026, with speaker, timestamp, and whether it was positive or negative."}'

External Transmission

Medium
Category
Data Exfiltration
Confidence
93% confidence
Finding

The /note request transmits analyst corrections and review notes to an external API, including human judgments and client-report commentary. This is sensitive because such notes may contain internal assessments, reputational conclusions, or workflow metadata that users may not expect to be stored outside their environment.

Content

Scanner excerpt · SKILL.md (reported line 57)May include surrounding context.

client report is defendable.

bash
curl -X POST https://api.bluecolumn.ai/note \
  -H "Authorization: Bearer $BLUECOLUMN_API_KEY" \
  -H "Content-Type: application/json" \
  -d '{"text": "The Money Hour 18:40 framed as positive-unprompted; 42:15 flagged as pricing objection to address in client report. Reviewed by analyst 09-19.", "tags": ["mention", "acme", "q3-report"]}'

Static analysis

No suspicious patterns detected.