Back to skill

Security audit

Sound Event Memory

Security checks for vulnerabilities and agentic risk

Overview

This skill is coherent and not deceptive, but it should be reviewed because it sends sensitive ambient audio, speech-derived data, incident queries, and audit notes to a third-party persistent memory service without enough privacy, retention, or consent guidance.

Install only if BlueColumn is an approved vendor for your environment and you have authority to process ambient audio from the monitored sites. Before using real cameras, doorbells, or sensors, confirm consent and recording-law requirements, avoid unnecessary site or personal identifiers, and verify retention, deletion, access-control, and audit policies with the provider.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Findings (6)

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

The skill instructs users to send ambient audio and related event data to a third-party API but does not clearly warn that audio may leave the local environment and be processed externally. Because the content involves potentially sensitive environmental and incidental speech data from cameras, doorbells, and sensors, the missing disclosure creates a real privacy and compliance risk for users operating in regulated or consent-sensitive jurisdictions.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The skill states that BlueColumn transcribes speech from ambient audio without documenting user choice, opt-in controls, or jurisdiction-specific privacy constraints. Ambient audio can capture bystanders, tenants, employees, or visitors, so enabling transcription by default can expose operators to unlawful interception, biometric/voice processing concerns, or policy violations.

Content

No source excerpt is available for this finding.

External Transmission

Medium
Category
Data Exfiltration
Confidence
91% confidence
Finding

The documented use of the BlueColumn API base confirms reliance on a third-party network destination for ingestion. While not malicious on its face, directing sensitive ambient audio workflows to an external processor increases exposure if users are unaware of the trust boundary or if the service is not contractually approved.

Content

Scanner excerpt · SKILL.md (reported line 29)May include surrounding context.

signals you care about so the detector focuses.

bash
curl -X POST https://api.bluecolumn.ai/remember \
  -H "Authorization: Bearer $BLUECOLUMN_API_KEY" \
  -H "Content-Type: application/json" \
  -d '{

External Transmission

Medium
Category
Data Exfiltration
Confidence
91% confidence
Finding

The documented use of the BlueColumn API base confirms reliance on a third-party network destination for ingestion. While not malicious on its face, directing sensitive ambient audio workflows to an external processor increases exposure if users are unaware of the trust boundary or if the service is not contractually approved.

Content

Scanner excerpt · SKILL.md (reported line 29)May include surrounding context.

signals you care about so the detector focuses.

bash
curl -X POST https://api.bluecolumn.ai/remember \
  -H "Authorization: Bearer $BLUECOLUMN_API_KEY" \
  -H "Content-Type: application/json" \
  -d '{

External Transmission

Medium
Category
Data Exfiltration
Confidence
88% confidence
Finding

The recall call sends investigative queries about incidents across devices and time to an external API, which can expose sensitive operational intelligence even if raw audio is not included. Query contents may reveal site names, event history, and security posture, making the transmission meaningful from a confidentiality perspective.

Content

Scanner excerpt · SKILL.md (reported line 44)May include surrounding context.

Ask a question, not a query string. The answer cites the device and timestamp.

bash
curl -X POST https://api.bluecolumn.ai/recall \
  -H "Authorization: Bearer $BLUECOLUMN_API_KEY" \
  -H "Content-Type: application/json" \
  -d '{"q": "Every glass-break or forced-door event at site7 in the last 30 days, with timestamp and confidence."}'

External Transmission

Medium
Category
Data Exfiltration
Confidence
90% confidence
Finding

The note endpoint transmits incident decisions, timestamps, site identifiers, and review outcomes to a third party. That information can contain sensitive audit trails or law-enforcement-relevant records, so sending it externally without explicit governance and disclosure creates confidentiality and compliance risk.

Content

Scanner excerpt · SKILL.md (reported line 58)May include surrounding context.

Keep the human call next to the evidence so audits are complete.

bash
curl -X POST https://api.bluecolumn.ai/note \
  -H "Authorization: Bearer $BLUECOLUMN_API_KEY" \
  -H "Content-Type: application/json" \
  -d '{"text": "site7 front-door 02:14 glass-break: confirmed false alarm (mirror fell in wind). Dispatched no unit. Reviewed by ops on 09-30.", "tags": ["incident", "site7", "false-alarm"]}'

Static analysis

No suspicious patterns detected.