Back to skill

Security audit

voice-to-job-memory

Security checks for vulnerabilities and agentic risk

Overview

This skill is a straightforward BlueColumn API workflow for storing and recalling field-service job notes, with the main risk being that job details and audio links are sent to a third-party service.

Before installing, confirm that BlueColumn is an approved service for your business data. Avoid sending unnecessary customer, property, employee, or confidential details, keep the API key in an environment variable, and review BlueColumn's privacy and retention terms for stored job notes and audio links.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Findings (6)

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The setup section instructs users to obtain a live API key and send requests to a third-party endpoint, but it does not plainly disclose that both credentials and job data will leave the local environment and be processed externally. This is dangerous because users may paste real production keys and customer/job content into a workflow without understanding the external exposure or applicable compliance obligations.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The skill explicitly says BlueColumn transcribes and stores field updates containing job details, measurements, customer changes, and unresolved questions, but it does not clearly warn users that this information is being sent to and retained by a third-party service. In a field-service context, these notes can contain customer, property, scheduling, and business-sensitive information, so omission of a clear disclosure creates a real privacy and data-governance risk.

Content

No source excerpt is available for this finding.

External Transmission

Medium
Category
Data Exfiltration
Confidence
88% confidence
Finding

This example transmits a voice-note URL and detailed job-update text to an external service for transcription and storage. The behavior is aligned with the skill's purpose, but it is still security-relevant because the payload can contain sensitive business and customer information, and the document does not pair the transmission with adequate caution, minimization guidance, or consent/privacy notice.

Content

Scanner excerpt · SKILL.md (reported line 19)May include surrounding context.

The worker talks; BlueColumn transcribes and stores the job update.

bash
curl -X POST https://api.bluecolumn.ai/remember \
  -H "Authorization: Bearer $BLUECOLUMN_API_KEY" \
  -H "Content-Type: application/json" \
  -d '{

External Transmission

Medium
Category
Data Exfiltration
Confidence
88% confidence
Finding

This example transmits a voice-note URL and detailed job-update text to an external service for transcription and storage. The behavior is aligned with the skill's purpose, but it is still security-relevant because the payload can contain sensitive business and customer information, and the document does not pair the transmission with adequate caution, minimization guidance, or consent/privacy notice.

Content

Scanner excerpt · SKILL.md (reported line 19)May include surrounding context.

The worker talks; BlueColumn transcribes and stores the job update.

bash
curl -X POST https://api.bluecolumn.ai/remember \
  -H "Authorization: Bearer $BLUECOLUMN_API_KEY" \
  -H "Content-Type: application/json" \
  -d '{

External Transmission

Medium
Category
Data Exfiltration
Confidence
50% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · SKILL.md (reported line 34)May include surrounding context.

The office recalls the latest site note when drafting the quote.

bash
curl -X POST https://api.bluecolumn.ai/recall \
  -H "Authorization: Bearer $BLUECOLUMN_API_KEY" \
  -H "Content-Type: application/json" \
  -d '{"q": "What did the field note say for job 441 — measurements, materials, customer changes, and open questions?"}'

External Transmission

Medium
Category
Data Exfiltration
Confidence
50% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · SKILL.md (reported line 43)May include surrounding context.

The office recalls the latest site note when drafting the quote.

bash
curl -X POST https://api.bluecolumn.ai/recall \
  -H "Authorization: Bearer $BLUECOLUMN_API_KEY" \
  -H "Content-Type: application/json" \
  -d '{"q": "What did the field note say for job 441 — measurements, materials, customer changes, and open questions?"}'

Static analysis

No suspicious patterns detected.