Back to skill

Security audit

buildlog

Security checks for vulnerabilities and agentic risk

Overview

The skill is coherent for recording and sharing coding sessions, but its public-by-default and file-content defaults create a real risk of unintentionally exposing private code or secrets.

Review the configuration before installing or using this skill. Set buildlogs private by default, disable file-content snapshots unless needed, and avoid uploading sessions that may contain secrets, proprietary code, credentials, customer data, or internal URLs.

Vulnerability Patterns
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (1)

T09 · Insecure Skill Coding Practices

Error
Location
SKILL.md:56
Finding

Unsafe Defaults Can Publicly Expose Session and File Contents

Content
View full analysis

Vulnerability Details

File Location: SKILL.md, lines 56–67
Vulnerability Type: Unsafe data-sharing configuration
Risk Level: High

The documented configuration enables public visibility and file-content collection by default:

json
{
  "skills": {
    "buildlog": {
      "apiKey": "your-api-key",
      "autoUpload": false,
      "defaultPublic": true,
      "includeFileContents": true,
      "maxFileSizeKb": 100
    }
  }
}

Technical Analysis

The combination of "defaultPublic": true and "includeFileContents": true creates an unsafe disclosure boundary. A buildlog may contain coding-session messages and snapshots of source files, which can include proprietary code, credentials, tokens, personal information, internal service URLs, or sensitive configuration.

Although automatic upload is disabled by default, the skill documents upload and sharing commands. When a user invokes those commands, collected file contents may be uploaded with public visibility unless the configuration is changed. The documentation does not require an exact export preview, file allowlist, secret scanning, redaction, or a separate confirmation of public visibility.

SKILL.md states that API keys are excluded from exports, but the project contains no implementation with which to verify that guarantee. The statement also does not address other classes of secrets that may appear in conversations or files.

Attack Path

  1. A user configures the skill using the documented defaults.
  2. The skill records a coding session while file-content collection is enabled.
  3. Sensitive information is included in session messages or captured file snapshots.
  4. The user invokes the documented upload or sharing functionality, or separately opts into automatic upload.
  5. Because public visibility is the documented default, the resulting buildlog is made publicly accessible unless the user proactively changes the settin ...[truncated 885 chars]
Remediation
View remediation

Remediation Suggestions

  1. Change defaultPublic to false so every buildlog is private unless the user explicitly selects public visibility.
  2. Change includeFileContents to false and require explicit opt-in for each recording or export.
  3. Display a preview listing every message, annotation, and file selected for export before upload.
  4. Require separate, informed confirmations for uploading data and making it public.
  5. Implement file allowlists and exclude sensitive paths and formats by default, including .env files, private keys, credential stores, deployment configuration, and authentication files.
  6. Scan exported messages and files for secrets, credentials, personal information, and high-entropy tokens; redact detected values or block the upload pending review.
  7. Keep autoUpload disabled and prevent it from bypassing content review or public-visibility confirmation.
  8. Document data retention, deletion, access controls, transport security, and server-side handling.
  9. Add implementation-level tests demonstrating that API keys and other detected secrets cannot enter exported artifacts.
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Findings (1)

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The skill is explicitly designed to record AI coding sessions and, by default, includes file contents and makes uploaded buildlogs public. However, the documentation does not prominently warn users that source files, prompts, responses, secrets in code/configs, and other sensitive conversation data may be captured and shared, which creates a meaningful risk of unintended data exposure.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.