Back to skill

Security audit

Data Reporter

Security checks for vulnerabilities and agentic risk

Overview

This reporting skill is coherent, but it handles sensitive business data and automated sharing without enough credential, access-control, or publication safeguards.

Install only if you are prepared to configure it with least-privilege, preferably read-only credentials, keep completed config and credential files out of source control, review every email/Slack/webhook/public-dashboard destination, and avoid public URLs for confidential reports unless access controls are added.

Vulnerability Patterns
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (1)

T09 · Insecure Skill Coding Practices

Warning
Location
SKILL.md:116
Finding

Report template encourages plaintext API credential storage

Content
View full analysis
= yesterday() status: "fulfilled" - name: "Stripe Payments" type: "stripe" config: api_key: "..." query: | created >= 24h ago status: "succeeded" - name: "Google Analytics" type: "google_analytics" config: view_id: "123456" credentials: "ga-credentials.json" ``` ### Technical Analysis The primary configuration example places Shopify and Stripe API-key fields directly inside a report YAML file. Although the values shown are placeholders, users are implicitly directed to replace them with live credentials. The documentation does not recommend environment-variable substitution, a secrets manager, restrictive file permissions, log redaction, or exclusion from source control. The Google Analytics configuration similarly references a local credential file without providing guidance about storage permissions or preventing accidental repository inclusion. This does not prove that credentials are currently exposed in the project, but it establishes an unsafe credential-handling pattern for users implementing the example. An attacker who obtains a completed configuration file or its repository history, backup, build artifact, support bundle, or logs may recover the embedded API keys. Whether those keys can be used for read-only access or state-changing operations depends on the permissions granted by the external provider. ### Attack Path 1. A user copies the documented report template. 2. The user replaces the `api_key: "..."` placeholders with active Shopify and Stripe API keys and stores a Google Analytic ...[truncated 1356 chars]
Remediation
View remediation
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Findings (3)

Credential Access

High
Category
Privilege Escalation
Confidence
70% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · SKILL.md (reported line 138)May include surrounding context.

md
type: "google_analytics"
      config:
        view_id: "123456"
        credentials: "ga-credentials.json"
      metrics:
        - sessions
        - revenue

Missing User Warnings

High
Category
Not specified by scanner
Confidence
98% confidence
Finding

The documentation explicitly supports publishing dashboards to a public URL but does not warn that this can expose sensitive operational or financial metrics to anyone possessing or discovering the link. In the context of a reporting skill handling business intelligence data, public publication materially raises the chance of confidentiality breaches, accidental indexing, and unauthorized third-party access.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

The skill markets broad connectivity to databases, APIs, spreadsheets, cloud storage, and outbound delivery channels without clearly warning users that it may access sensitive business data, credentials, and external recipients. This increases the risk of overbroad deployment, accidental data exfiltration, or unsafe credential handling because operators are not prompted to apply least privilege or review destinations carefully.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.