Back to skill

Security audit

voice-lead-recovery

Security checks for vulnerabilities and agentic risk

Overview

This skill clearly teaches users how to send voicemail lead data to BlueColumn, and that external storage is expected for its stated purpose.

Install only if you intend to use BlueColumn for lead memory and are authorized to send call recordings, phone numbers, and follow-up notes there. Avoid sending unnecessary personal details, and check BlueColumn's retention and privacy terms for your business requirements.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Findings (5)

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The skill instructs sending voicemail audio, phone numbers, names, scheduling details, and conversational content to a third-party API, but it does not require any user-facing consent, privacy notice, or data-minimization step. Because this is customer lead data and may include sensitive personal information, the omission creates a real privacy and compliance risk rather than a purely informational issue.

Content

No source excerpt is available for this finding.

External Transmission

Medium
Category
Data Exfiltration
Confidence
96% confidence
Finding

This endpoint sends externally hosted voicemail audio plus a structured summary containing a caller's name, phone number, service request, urgency, objections, and follow-up commitments to a third-party service. In the context of call recordings and lead management, this is a meaningful exfiltration/privacy risk if done without notice, consent, or validation that the operator is permitted to share the data.

Content

Scanner excerpt · SKILL.md (reported line 19)May include surrounding context.

Send the voicemail or call audio; BlueColumn transcribes it and stores the structured lead.

bash
curl -X POST https://api.bluecolumn.ai/remember \
  -H "Authorization: Bearer $BLUECOLUMN_API_KEY" \
  -H "Content-Type: application/json" \
  -d '{

External Transmission

Medium
Category
Data Exfiltration
Confidence
96% confidence
Finding

This endpoint sends externally hosted voicemail audio plus a structured summary containing a caller's name, phone number, service request, urgency, objections, and follow-up commitments to a third-party service. In the context of call recordings and lead management, this is a meaningful exfiltration/privacy risk if done without notice, consent, or validation that the operator is permitted to share the data.

Content

Scanner excerpt · SKILL.md (reported line 19)May include surrounding context.

Send the voicemail or call audio; BlueColumn transcribes it and stores the structured lead.

bash
curl -X POST https://api.bluecolumn.ai/remember \
  -H "Authorization: Bearer $BLUECOLUMN_API_KEY" \
  -H "Content-Type: application/json" \
  -d '{

External Transmission

Medium
Category
Data Exfiltration
Confidence
90% confidence
Finding

The recall step sends a caller's phone number and asks the third-party API to retrieve prior history and promises, which can expose accumulated customer interaction data to an external processor. While less severe than uploading raw audio, it still involves sharing identifying information and business context without any access-control, consent, or privacy guidance in the skill.

Content

Scanner excerpt · SKILL.md (reported line 34)May include surrounding context.

Pull the caller's history and open promises the moment you have the number.

bash
curl -X POST https://api.bluecolumn.ai/recall \
  -H "Authorization: Bearer $BLUECOLUMN_API_KEY" \
  -H "Content-Type: application/json" \
  -d '{"q": "What do we know about Dana 602-555-0147 and what did we promise?"}'

External Transmission

Medium
Category
Data Exfiltration
Confidence
91% confidence
Finding

The note endpoint stores follow-up outcomes and preferences such as appointment time, financing material, and communication preferences with an external service. This continues building a customer profile at a third party and may include personal or potentially sensitive business/customer information without warning users or limiting the scope of shared data.

Content

Scanner excerpt · SKILL.md (reported line 45)May include surrounding context.

After the call, store the result so the next touch is informed.

bash
curl -X POST https://api.bluecolumn.ai/note \
  -H "Authorization: Bearer $BLUECOLUMN_API_KEY" \
  -H "Content-Type: application/json" \
  -d '{"text": "Dana booked inspection 09-30 10:00. Send financing PDF before visit. If not home, text instead of call.", "tags": ["lead", "roofing", "scheduled"]}'

Static analysis

No suspicious patterns detected.