Back to skill

Security audit

Coffee Chat Playbook Generator

Security checks for vulnerabilities and agentic risk

Overview

The skill is a coherent coffee-chat research helper, but it needs review because it combines social scraping, third-party export, persistent credentials, and an unsafe shell example.

Review before installing. Use only public information for legitimate networking preparation, avoid scraping unless you are comfortable with the platform and privacy implications, do not paste untrusted X handles into the provided shell command, and store Notion or Apify tokens in a proper credential store rather than a shell profile. Treat Notion export as sending the playbook and researched personal details to a third-party workspace.

Vulnerability Patterns
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
Findings (3)

T09 · Insecure Skill Coding Practices

Error
Location
SKILL.md:159
Finding

Shell Command Injection Through an Unvalidated X Username

Content
View full analysis
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Warning
Location
SKILL.md:59
Finding

Notion API Token Persisted in a Plaintext Shell Startup File

Content
View full analysis
> ~/.zshrc ``` ### Technical Analysis The setup instructions recommend writing the Notion integration token directly into `~/.zshrc`. This stores a long-lived credential in plaintext and exports it into the environment of subsequently launched shell processes. Shell startup files can be exposed through overly broad filesystem permissions, workstation backups, diagnostic bundles, accidental repository inclusion, screen sharing, or unrelated processes that inherit the environment. Persistently exporting the token also increases the number of child processes that may receive it even when they do not need Notion access. Although the example contains a placeholder rather than a real embedded secret, users are explicitly instructed to replace it with their actual credential. ### Attack Path 1. A user replaces the placeholder with a real Notion integration token. 2. The user runs the documented command, permanently writing the token to `~/.zshrc`. 3. The token is exposed through local file access, backups, accidental sharing, or process-environment inheritance. 4. An attacker obtains the token and submits authenticated requests to the Notion API. 5. The attacker accesses or modifies content within the permissions granted to that integration. ### Impact Assessment The exposed token can grant access to Notion pages and databases explicitly shared with the integration. The precise scope depends on the integration's configured capabilities and shared resources. Potential impact includes: - Unauthorized reading of private playbooks and profile information. - Disclosure of personal or professional contact data. - Modi ...[truncated 374 chars]
Remediation
View remediation

T08 · Insecure Dependencies

Warning
Location
SKILL.md:31
Finding

Unpinned Apify CLI and Mutable Third-Party Scraper Actor

Content
View full analysis
Remediation
View remediation
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Rogue AgentSelf-Modification, Session Persistence
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
Findings (7)

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

This markdown skill explicitly lists trigger phrases, but some are broad enough to overlap with ordinary requests unrelated to networking coffee chats. Terms like "meeting prep" and "chat playbook" lack domain constraints, increasing the chance of unintended activation.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

The manifest presents the skill as simple coffee-chat preparation, but the body expands into broader intelligence gathering, including scraping X/Twitter content and optionally exporting results to Notion. That mismatch can mislead users and reviewers about the true data collection and transmission scope, increasing the chance that personal data is gathered or shared without informed consent.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

The skill instructs the agent to collect and scrape personal profile and social-media data, including LinkedIn and X content, without an explicit privacy notice, consent boundary, or guidance on lawful/appropriate use. In context, this makes accidental over-collection and inappropriate profiling of third parties more likely.

Content

No source excerpt is available for this finding.

Session Persistence

Medium
Category
Rogue Agent
Confidence
60% confidence
Finding

Skill establishes unauthorized persistence across sessions via cron jobs, startup scripts, or state files. Session persistence allows an attacker to maintain access beyond the current interaction.

Content

Scanner excerpt · SKILL.md (reported line 56)May include surrounding context.

md
### 2. Notion Integration (optional — for saving playbooks to Notion)

**Create an integration:**
1. Go to https://www.notion.so/my-integrations
2. Click **"New integration"**
3. Give it a name (e.g. "Coffee Chat Skill")

External Transmission

Medium
Category
Data Exfiltration
Confidence
89% confidence
Finding

Referencing the Notion API endpoint reflects a built-in mechanism for sending collected intelligence off-platform. In this skill's context, the danger is not the domain itself but that researched personal data may be persisted externally without sufficient privacy guardrails or user awareness.

Content

Scanner excerpt · SKILL.md (reported line 615)May include surrounding context.

md
NOTION_PAGE_ID="YOUR_NOTION_PAGE_ID"
NOTION_KEY="${NOTION_API_KEY}"

curl -s -X PATCH "https://api.notion.com/v1/blocks/${NOTION_PAGE_ID}/children" \
  -H "Authorization: Bearer $NOTION_KEY" \
  -H "Notion-Version: 2022-06-28" \
  -H "Content-Type: application/json" \

External Transmission

Medium
Category
Data Exfiltration
Confidence
89% confidence
Finding

Referencing the Notion API endpoint reflects a built-in mechanism for sending collected intelligence off-platform. In this skill's context, the danger is not the domain itself but that researched personal data may be persisted externally without sufficient privacy guardrails or user awareness.

Content

Scanner excerpt · SKILL.md (reported line 615)May include surrounding context.

md
NOTION_PAGE_ID="YOUR_NOTION_PAGE_ID"
NOTION_KEY="${NOTION_API_KEY}"

curl -s -X PATCH "https://api.notion.com/v1/blocks/${NOTION_PAGE_ID}/children" \
  -H "Authorization: Bearer $NOTION_KEY" \
  -H "Notion-Version: 2022-06-28" \
  -H "Content-Type: application/json" \

Context-Inappropriate Capability

Low
Category
Not specified by scanner
Confidence
76% confidence
Finding

The stated purpose is to generate a personalized coffee chat playbook for meeting preparation. Persisting that output to a third-party workspace via Notion is an extra integration capability beyond preparing the playbook itself, and the manifest does not frame remote publication/storage as part of the skill's purpose.

Content

No source excerpt is available for this finding.

Static analysis

Detected: suspicious.exposed_secret_literal, suspicious.generated_source_template_injection

File appears to expose a hardcoded API secret or token.

Critical
Code
suspicious.exposed_secret_literal
Location
SKILL.md:64

User-controlled placeholder is embedded directly into generated source code.

Critical
Code
suspicious.generated_source_template_injection
Location
SKILL.md:613