Back to skill

Security audit

Backboard.io

Security checks for vulnerabilities and agentic risk

Overview

The skill has a coherent Backboard integration purpose, but its backend exposes powerful account operations on a network-accessible unauthenticated development server.

Review before installing. Only run this backend on a trusted machine, bind it to 127.0.0.1, add authentication before use, avoid exposing port 5100 to a LAN or container network, and do not upload sensitive documents or store sensitive memories unless you accept Backboard and model-provider processing and retention. Pin dependencies before routine startup use.

Vulnerability Patterns
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
Findings (4)

T05 · Unauthorized Access and Privilege Escalation

Error
Location
backend/api/app.py:54
Finding

Privileged Backboard API Operations Are Exposed Without Authentication or Authorization

Content
View full analysis
", methods=["GET"]) def get_assistant(assistant_id: str): """Get an assistant by ID.""" try: service = get_service() result = service.get_assistant(assistant_id) return jsonify(result) except BackboardNotFoundError: return jsonify({"error": "Not found", "detail": "Assistant not found"}), 404 except BackboardAPIError as e: return jsonify({"error": "API error", "detail": str(e)}), 500 @bp.route("/", methods=["PATCH"]) def update_assistant(assistant_id: str): """Update an assistant.""" try: data = AssistantUpdate.model_validate(request.json) service = get_service() result = service.update_assistant( assistant_id=assistant_id, name=data.name, system_prompt=data.system_prompt, ) return jsonify(result) except BackboardNotFoundError: return jsonify({"error": "Not found", "detail": "Assistant not found"}), 404 except BackboardValidationError as e: return jsonify({"error": "Validation error", "detail": str(e)}), 400 except BackboardAPIError as e: return jsonify({"error": "API error", "detail": str(e)}), 50 ...[truncated 5193 chars]
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Error
Location
backend/start.sh:25
Finding

Unauthenticated Development Server Is Bound to All Network Interfaces

Content
View full analysis
Remediation
View remediation

T08 · Insecure Dependencies

Warning
Location
backend/pyproject.toml:7
Finding

Runtime Installation Uses Unbounded Dependencies Without a Lockfile or Hash Verification

Content
View full analysis
=3.0.0", "backboard-sdk>=1.4.11", "pydantic>=2.0.0", "python-dotenv>=1.0.0", ] ``` The startup script installs the project and resolves dependencies each time it runs: ```bash # Install dependencies if needed if [ ! -d ".venv" ]; then echo "Creating virtual environment..." uv venv fi echo "Installing dependencies..." uv pip install -e . ``` ### Technical Analysis Every dependency is specified only with a lower version boundary. There is no reviewed lockfile or hash verification in the supplied project. Consequently, a startup performed at a later time can resolve materially different package versions from those originally reviewed. Because installation is part of routine application startup, availability and integrity depend on the current state of external package repositories. A compromised maintainer account, malicious package release, or newly incompatible release could introduce unreviewed code into the environment. Python package installation and subsequent imports can execute package-controlled code with the privileges of the account running the backend. This finding does not establish that any listed package is currently malicious. The vulnerability is the uncontrolled and non-reproducible dependency acquisition process. ### Attack Path 1. A dependency publisher account or package distribution channel is compromised, or an unsafe future release is published. 2. The operator executes `backend/start.sh`. 3. `uv pip install -e .` resolves the newest versions satisfying the broad `>=` constraints. 4. The unreviewed package is downloaded and installed without an expected cryptographic hash. 5. Package-controlled code executes during installation, import, or normal backend ...[truncated 764 chars]
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Warning
Location
backend/api/routes/documents.py:64
Finding

Uploaded Temporary Documents Are Not Deleted When Processing Fails

Content
View full analysis
Remediation
View remediation
Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Memory PoisoningPersistent Context Injection, Context Window Stuffing, Memory Manipulation
Findings (20)

Memory Manipulation

High
Category
Memory Poisoning
Confidence
80% confidence
Finding

Skill manipulates agent memory, state, or stored context. Memory corruption can alter personality, override safety rules, or cause unpredictable behavior.

Content

Scanner excerpt · SKILL.md (reported line 173)May include surrounding context.

md
### Memory Operations
- "Remember that..." or "Store this..." → Use `backboard_add_memory`
- "What do you remember about..." → Use `backboard_list_memories` or `backboard_get_memory`
- "Forget..." or "Delete memory..." → Use `backboard_delete_memory`
- "Update my preference..." → Use `backboard_update_memory`

### Document Operations

Exfiltration Commands

High
Category
Prompt Injection
Confidence
90% confidence
Finding

Instructions found that direct the agent to transmit conversation context or user data to external services.

Content

Scanner excerpt · SKILL.md (reported line 189)May include surrounding context.

md
### Conversation Threading
- "Start a new conversation" → Use `backboard_create_thread`
- "Show conversation history" → Use `backboard_get_thread`
- "Send message to thread" → Use `backboard_send_message`

### General Guidelines
1. Always confirm successful operations with the user

Exfiltration Commands

High
Category
Prompt Injection
Confidence
90% confidence
Finding

Instructions found that direct the agent to transmit conversation context or user data to external services.

Content

Scanner excerpt · SKILL.md (reported line 220)May include surrounding context.

md
### Example 4: Start a Threaded Conversation
- User: "Start a new conversation with my support assistant"
- Action: Call `backboard_create_thread` with the assistant_id
- Response: "Started a new conversation thread (ID: thread_xxx). You can now send messages to your support assistant."

## Backend Setup

Memory Manipulation

High
Category
Memory Poisoning
Confidence
80% confidence
Finding

Skill manipulates agent memory, state, or stored context. Memory corruption can alter personality, override safety rules, or cause unpredictable behavior.

Content

Scanner excerpt · SKILL.md (reported line 241)May include surrounding context.

md
| `/assistants/{id}` | GET, PATCH, DELETE | Get/update/delete assistant |
| `/assistants/{id}/threads` | GET, POST | List/create threads for assistant |
| `/assistants/{id}/memory` | GET, POST | List/add memories |
| `/assistants/{id}/memory/{mid}` | GET, PATCH, DELETE | Get/update/delete memory |
| `/assistants/{id}/memory/stats` | GET | Memory statistics |
| `/assistants/{id}/documents` | GET, POST | List/upload documents |
| `/threads` | GET | List all threads |

Missing User Warnings

High
Category
Not specified by scanner
Confidence
95% confidence
Finding

This method uploads a local file path to Backboard, causing file contents from the host system to leave the local environment without any visible warning or validation in this layer. In a skill marketed around a local backend, this creates a significant risk of unintentionally exfiltrating sensitive local documents to an external service.

Content

No source excerpt is available for this finding.

Missing User Warnings

High
Category
Not specified by scanner
Confidence
95% confidence
Finding

Uploading thread documents by file path sends local file contents to an external API with no visible consent, path restrictions, or sensitivity checks in this code path. The mismatch between 'local backend' framing and remote document transfer makes unintended disclosure more likely and increases the severity.

Content

No source excerpt is available for this finding.

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
91% confidence
Finding

The skill describes a backend setup that depends on an environment variable (BACKBOARD_API_KEY) and a local service, but the manifest does not declare tool scope or permissions boundaries. In practice, undeclared capabilities make it harder to reason about what the skill may access and increase the risk of over-privileged execution or accidental exposure of secrets in agent runtimes.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
90% confidence
Finding

The skill documents delete operations for assistants without cautionary guidance, confirmation requirements, or recovery expectations. This can lead to accidental destructive actions, especially in agent-driven workflows where IDs may be selected or reused incorrectly.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The skill offers persistent memory storage and document upload/RAG features but does not provide clear warnings about retention, sensitivity, sharing boundaries, or deletion semantics. Users may store secrets, personal data, or proprietary files without informed consent, creating avoidable privacy and compliance risk.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
87% confidence
Finding

This code saves user-provided files to a temporary local file and then uploads them through BackboardService, which is a data-handling operation affecting user content and privacy. The route contains no confirmation prompt or user-facing disclosure about local temporary storage or onward transmission of the file.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
84% confidence
Finding

The DELETE route removes a document, which is an irreversible or destructive action, but the code provides no confirmation step, warning message, or explanatory comment indicating that users are informed before deletion. Under this rule, destructive operations should have some form of disclosure unless clearly covered elsewhere in the skill description.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
82% confidence
Finding

This code exposes a DELETE route that removes a thread, but the handler contains no confirmation step, warning message, or other user disclosure around the destructive action. While deletion is part of the route's purpose, the implementation itself provides no visible safeguard or explicit warning before an irreversible operation is carried out.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
88% confidence
Finding

This method forwards user-provided message content to the Backboard service without any disclosure, consent gate, or policy enforcement visible in this code path. In a skill presented as using a local backend, that can mislead users into sharing sensitive prompts or data that are actually sent to a third-party API.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
89% confidence
Finding

Memory content and metadata may contain long-lived sensitive information, and this code sends both to the external Backboard API with no visible notice or minimization. Because memories are persistent by nature, accidental exfiltration can have broader privacy and compliance impact than a transient chat message.

Content

No source excerpt is available for this finding.

Missing User Warnings

Low
Category
Not specified by scanner
Confidence
81% confidence
Finding

This code file exposes a DELETE route that performs an irreversible operation via service.delete_assistant(assistant_id). While the function has a terse docstring, there is no confirmation prompt, user-facing log/message, or explicit warning in the code about the destructive nature of deleting an assistant.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

Low
Category
Not specified by scanner
Confidence
76% confidence
Finding

The manifest describes integration with Backboard via a local backend on http://localhost:5100, which suggests a local service wrapper rather than direct credential handling. This module loads a Backboard API key and default model/provider settings from environment variables, adding a credential-management capability not clearly justified by that stated purpose.

Content

No source excerpt is available for this finding.

Unverifiable Dependency: flask has 10 known advisory(ies) (CVE-2025-47278 (Flask uses fallback key instead of current signing key); CVE-2018-1000656 (Flask is vulnerable to Denial of Service via incorrect encoding of JSON data); CVE-2019-1010083 (Pallets Project Flask is vulnerable to Denial of Service via Unexpected memory u) +7 more), but the manifest does not pin a version, so it is unknown whether the installed release is affected

Low
Category
Supply Chain
Confidence
40% confidence
Finding

Dependency has known vulnerabilities (CVEs). Using packages with unpatched security flaws exposes the environment to known exploits.

Content

No source excerpt is available for this finding.

Unverifiable Dependency: pydantic has 4 known advisory(ies) (CVE-2021-29510 (Use of "infinity" as an input to datetime and date fields causes infinite loop i); CVE-2024-3772 (Pydantic regular expression denial of service); CVE-2021-29510 (Pydantic is a data validation and settings management using Python type hinting.) +1 more), but the manifest does not pin a version, so it is unknown whether the installed release is affected

Low
Category
Supply Chain
Confidence
40% confidence
Finding

Dependency has known vulnerabilities (CVEs). Using packages with unpatched security flaws exposes the environment to known exploits.

Content

No source excerpt is available for this finding.

Unverifiable Dependency: python-dotenv has 2 known advisory(ies) (CVE-2026-28684 (python-dotenv: Symlink following in set_key allows arbitrary file overwrite via ); CVE-2026-28684 (python-dotenv reads key-value pairs from a .env file and can set them as environ)), but the manifest does not pin a version, so it is unknown whether the installed release is affected

Low
Category
Supply Chain
Confidence
40% confidence
Finding

Dependency has known vulnerabilities (CVEs). Using packages with unpatched security flaws exposes the environment to known exploits.

Content

No source excerpt is available for this finding.

Unverifiable Dependency: pytest has 2 known advisory(ies) (CVE-2025-71176 (pytest has vulnerable tmpdir handling); CVE-2025-71176 (pytest has vulnerable tmpdir handling)), but the manifest does not pin a version, so it is unknown whether the installed release is affected

Low
Category
Supply Chain
Confidence
40% confidence
Finding

Dependency has known vulnerabilities (CVEs). Using packages with unpatched security flaws exposes the environment to known exploits.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.