Back to skill

Security audit

voice-agent-quality

Security checks for vulnerabilities and agentic risk

Overview

This skill is a straightforward BlueColumn voice-call quality workflow, but users should treat uploaded recordings, transcripts, and QA notes as sensitive third-party data.

Before installing, confirm you are allowed to send call recordings, transcripts, customer details, and internal QA notes to BlueColumn. Use consented or redacted data where possible, protect the API key, and review BlueColumn retention and deletion controls for your account.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Findings (5)

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

The skill instructs users to upload call recordings and transcripts to a third-party API but does not clearly warn about external transmission of potentially sensitive audio, personal data, or regulated communications data. In this context, omission of a privacy/data-handling warning is dangerous because users may submit customer calls without informed consent, legal review, or redaction, increasing compliance and data exposure risk.

Content

No source excerpt is available for this finding.

External Transmission

Medium
Category
Data Exfiltration
Confidence
98% confidence
Finding

This step sends a call recording reference and detailed transcript content to an external service for transcription and analysis. Because the data includes customer conversation details, timestamps, policy statements, and potentially personal or confidential business information, the transmission materially increases privacy, confidentiality, and compliance risk if users are not warned or if the source audio URL is broadly accessible.

Content

Scanner excerpt · SKILL.md (reported line 19)May include surrounding context.

Send the recording; BlueColumn transcribes it for analysis.

bash
curl -X POST https://api.bluecolumn.ai/remember \
  -H "Authorization: Bearer $BLUECOLUMN_API_KEY" \
  -H "Content-Type: application/json" \
  -d '{

External Transmission

Medium
Category
Data Exfiltration
Confidence
98% confidence
Finding

This step sends a call recording reference and detailed transcript content to an external service for transcription and analysis. Because the data includes customer conversation details, timestamps, policy statements, and potentially personal or confidential business information, the transmission materially increases privacy, confidentiality, and compliance risk if users are not warned or if the source audio URL is broadly accessible.

Content

Scanner excerpt · SKILL.md (reported line 19)May include surrounding context.

Send the recording; BlueColumn transcribes it for analysis.

bash
curl -X POST https://api.bluecolumn.ai/remember \
  -H "Authorization: Bearer $BLUECOLUMN_API_KEY" \
  -H "Content-Type: application/json" \
  -d '{

External Transmission

Medium
Category
Data Exfiltration
Confidence
90% confidence
Finding

The recall operation queries an external service across previously stored reviewed calls, which can expose aggregated call-analysis content and operational intelligence outside the local environment. While less sensitive than initial audio upload, it still relies on external retention and processing of potentially sensitive customer-support and business-performance data.

Content

Scanner excerpt · SKILL.md (reported line 34)May include surrounding context.

Ask which problems recur, not just which calls failed.

bash
curl -X POST https://api.bluecolumn.ai/recall \
  -H "Authorization: Bearer $BLUECOLUMN_API_KEY" \
  -H "Content-Type: application/json" \
  -d '{"q": "Across all reviewed calls for booking-bot-v3, which quality issues repeat most, and at what timestamps?"}'

External Transmission

Medium
Category
Data Exfiltration
Confidence
88% confidence
Finding

This note operation sends internal remediation details, deployment timing, and agent-specific quality issues to a third-party API. Such notes can reveal internal workflows, business policies, and incident history, which may be sensitive if the vendor account is misconfigured or compromised.

Content

Scanner excerpt · SKILL.md (reported line 45)May include surrounding context.

Track what you changed so you can measure whether it worked.

bash
curl -X POST https://api.bluecolumn.ai/note \
  -H "Authorization: Bearer $BLUECOLUMN_API_KEY" \
  -H "Content-Type: application/json" \
  -d '{"text": "Fixed booking-bot-v3 pricing prompt: added exact cancellation policy (48h, 20%). Deploy 09-30. Re-check handoff phrase after 20 calls.", "tags": ["qa", "fix", "booking-bot-v3"]}'

Static analysis

No suspicious patterns detected.