Back to skill

Security audit

Nerve Kanban Bwm

Security checks for vulnerabilities and agentic risk

Overview

This skill is a coherent Kanban API helper, but it gives an agent live board mutation, permanent deletion, auto-approval, and subagent execution abilities without enough scoping or confirmation guidance.

Review this skill before installing if the Kanban board contains important work data. Only use it where the local Nerve API is trusted, require explicit user confirmation for delete, execute, approve/reject, complete, and config updates, and avoid enabling proposalPolicy auto unless the board is intentionally configured for autonomous agent changes.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Tool MisuseTool Parameter Abuse, Chaining Abuse, Unsafe Defaults
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
Findings (19)

Tool Parameter Abuse

High
Category
Tool Misuse
Confidence
86% confidence
Finding

The skill exposes a permanent DELETE /api/kanban/tasks/:id operation, which is a high-risk destructive capability in an agent context because an LLM or automation layer may invoke it from ambiguous user instructions or prompt injection. Since the docs present deletion as a straightforward operation and mention permanence, misuse could irreversibly remove task records and disrupt workflow integrity.

Content

Scanner excerpt · references/api.md (reported line 265)May include surrounding context.

md
---

### DELETE /api/kanban/tasks/:id

Permanently delete a task.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

This markdown file documents deletion, task execution, approval/rejection, abort, and configuration update operations, but it does not warn users that these actions can permanently alter board state or trigger downstream agent activity. For markdown files, SQP-2 applies when descriptions omit warnings about behaviors that could affect user data or system integrity.

Content

No source excerpt is available for this finding.

External Transmission

Medium
Category
Data Exfiltration
Confidence
60% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · references/api.md (reported line 210)May include surrounding context.

Response: 201 with KanbanTask. ID is a URL-safe slug derived from title.

bash
curl -X POST http://localhost:3000/api/kanban/tasks \
  -H 'Content-Type: application/json' \
  -d '{
    "title": "Fix login bug",

External Transmission

Medium
Category
Data Exfiltration
Confidence
60% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · references/api.md (reported line 254)May include surrounding context.

Errors: 409 version_conflict if version mismatches (response includes serverVersion and latest task).

bash
curl -X PATCH http://localhost:3000/api/kanban/tasks/fix-login-bug \
  -H 'Content-Type: application/json' \
  -d '{
    "version": 1,

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
97% confidence
Finding

The docs describe permanent task deletion but do not emphasize irreversibility or recommend confirmation/authorization controls. In an agent-integrated workflow, destructive endpoints can be invoked programmatically, so weak warning language increases the risk of accidental or over-broad deletion.

Content

No source excerpt is available for this finding.

External Transmission

Medium
Category
Data Exfiltration
Confidence
60% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · references/api.md (reported line 300)May include surrounding context.

Errors: 409 version_conflict on stale version.

bash
curl -X POST http://localhost:3000/api/kanban/tasks/fix-login-bug/reorder \
  -H 'Content-Type: application/json' \
  -d '{ "version": 2, "targetStatus": "in-progress", "targetIndex": 0 }'

External Transmission

Medium
Category
Data Exfiltration
Confidence
60% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · references/api.md (reported line 327)May include surrounding context.

Side effects: Spawns a gateway subagent session with label kb-<id>. Background poller watches for completion and auto-transitions to review.

bash
curl -X POST http://localhost:3000/api/kanban/tasks/fix-login-bug/execute \
  -H 'Content-Type: application/json' \
  -d '{ "model": "claude-sonnet-4-20250514" }'

External Transmission

Medium
Category
Data Exfiltration
Confidence
60% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · references/api.md (reported line 351)May include surrounding context.

Errors: 409 invalid_transition if not in review.

bash
curl -X POST http://localhost:3000/api/kanban/tasks/fix-login-bug/approve \
  -H 'Content-Type: application/json' \
  -d '{ "note": "Looks good, merging." }'

External Transmission

Medium
Category
Data Exfiltration
Confidence
60% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · references/api.md (reported line 375)May include surrounding context.

Errors: 409 invalid_transition if not in review.

bash
curl -X POST http://localhost:3000/api/kanban/tasks/fix-login-bug/reject \
  -H 'Content-Type: application/json' \
  -d '{ "note": "Missed edge case with unicode chars. Retry." }'

External Transmission

Medium
Category
Data Exfiltration
Confidence
60% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · references/api.md (reported line 399)May include surrounding context.

Errors: 409 invalid_transition if not in in-progress with an active run.

bash
curl -X POST http://localhost:3000/api/kanban/tasks/fix-login-bug/abort \
  -H 'Content-Type: application/json' \
  -d '{ "note": "Taking too long, will rethink approach." }'

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

The documentation exposes a state-changing /complete endpoint that can be called externally and changes task status, stores agent output, or forces an error path back to todo. Without an explicit warning about authentication, origin restrictions, or webhook trust requirements, integrators may treat it as a normal public API and accidentally create a spoofable completion channel.

Content

No source excerpt is available for this finding.

External Transmission

Medium
Category
Data Exfiltration
Confidence
60% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · references/api.md (reported line 427)May include surrounding context.

bash
# Success
curl -X POST http://localhost:3000/api/kanban/tasks/fix-login-bug/complete \
  -H 'Content-Type: application/json' \
  -d '{ "result": "Fixed the bug. Escaped special chars in auth handler." }'

Autonomous Decision Making

Medium
Category
Excessive Agency
Confidence
87% confidence
Finding

Documenting proposalPolicy: 'auto' means agent-generated proposals can be applied without human confirmation, enabling autonomous state changes and task creation/updates. In a kanban system that can trigger execution and workflow transitions, removing approval gates increases the risk of unintended or manipulated actions.

Content

Scanner excerpt · references/api.md (reported line 464)May include surrounding context.

md
| `reviewRequired` | boolean | |
| `allowDoneDragBypass` | boolean | |
| `quickViewLimit` | number (1-50) | |
| `proposalPolicy` | `'confirm'` \| `'auto'` | `auto` = proposals auto-approve |
| `defaultModel` | string (max 100) | Default model for task execution |
| `defaultThinking` | ThinkingLevel | Default thinking level |

External Transmission

Medium
Category
Data Exfiltration
Confidence
60% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · references/api.md (reported line 476)May include surrounding context.

Response: 200 with full updated KanbanBoardConfig.

bash
curl -X PUT http://localhost:3000/api/kanban/config \
  -H 'Content-Type: application/json' \
  -d '{
    "proposalPolicy": "auto",

External Transmission

Medium
Category
Data Exfiltration
Confidence
60% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · references/api.md (reported line 553)May include surrounding context.

bash
# Agent proposes a new task
curl -X POST http://localhost:3000/api/kanban/proposals \
  -H 'Content-Type: application/json' \
  -d '{
    "type": "create",

External Transmission

Medium
Category
Data Exfiltration
Confidence
60% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · references/api.md (reported line 610)May include surrounding context.

  • 409 already_resolved if already resolved.
bash
curl -X POST http://localhost:3000/api/kanban/proposals/abc-uuid/reject \
  -H 'Content-Type: application/json' \
  -d '{ "reason": "Not needed right now." }'

Internal Network Request

Medium
Category
Server-Side Request Forgery
Confidence
70% confidence
Finding

Code issues a request to a loopback, link-local, or private-range host. This can reach internal services not meant to be exposed and is a common SSRF pivot.

Content

Scanner excerpt · references/api.md (reported line 643)May include surrounding context.

javascript
// List todo tasks
const res = await fetch('http://localhost:3000/api/kanban/tasks?status=todo');
const { items, total, hasMore } = await res.json();

// Create a task

Internal Network Request

Medium
Category
Server-Side Request Forgery
Confidence
70% confidence
Finding

Code issues a request to a loopback, link-local, or private-range host. This can reach internal services not meant to be exposed and is a common SSRF pivot.

Content

Scanner excerpt · references/api.md (reported line 647)May include surrounding context.

javascript
// List todo tasks
const res = await fetch('http://localhost:3000/api/kanban/tasks?status=todo');
const { items, total, hasMore } = await res.json();

// Create a task

External Transmission

Medium
Category
Data Exfiltration
Confidence
60% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · references/api.md (reported line 647)May include surrounding context.

md
const { items, total, hasMore } = await res.json();

// Create a task
const task = await fetch('http://localhost:3000/api/kanban/tasks', {
  method: 'POST',
  headers: { 'Content-Type': 'application/json' },
  body: JSON.stringify({

Static analysis

No suspicious patterns detected.