Back to skill

Security audit

Galileo TypeScript sdk

Security checks for vulnerabilities and agentic risk

Overview

This is a coherent Galileo SDK reference skill, but users should be aware that its examples can upload LLM traces and application data to Galileo.

Before installing or using this skill, confirm that sending Galileo traces is acceptable for your application data. Prefer API keys stored in a secret manager, avoid logging secrets or regulated data, consider redaction or sampling, and pin dependency versions in production or CI.

Vulnerability Patterns
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (1)

T08 · Insecure Dependencies

Warning
Location
SKILL.md:28
Finding

Unpinned Third-Party SDK Installation

Content
View full analysis
Remediation
View remediation
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Findings (6)

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

The skill repeatedly promotes automatic logging and trace upload of LLM activity, but does not clearly warn that prompts, responses, retrieved context, and tool data may be transmitted to Galileo. In an observability SDK, this omission can cause operators to unknowingly export sensitive application or user data to a third-party service, creating privacy, compliance, and data-handling risk.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
88% confidence
Finding

The authentication guidance presents username/password environment variables as an alternative without strongly discouraging their use or emphasizing their sensitivity relative to scoped API keys. This can lead users to store high-value credentials in developer environments, CI, or shared shells, increasing the chance of credential leakage and broader account compromise.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
90% confidence
Finding

The best-practices section instructs users to always call flush() to upload traces, but does not clearly state that flushing may transmit logged application content off-system to Galileo. In production server contexts, users may follow this guidance without realizing each request could send sensitive user prompts, outputs, or internal context to an external service.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

This markdown file documents configuring an OTLP exporter to send traces to a remote Galileo endpoint and includes use of an API key from environment variables. The surrounding documentation does not warn that enabling this instrumentation may transmit prompts, model interactions, or other application metadata off-box, which is a privacy-relevant behavior for a markdown skill description.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
89% confidence
Finding

The Mastra example configures an OTLP exporter endpoint and authorization header, implying that runtime telemetry will be exported to a third-party service. The markdown does not include any warning about possible privacy or data-handling impact, which is expected for documentation describing telemetry export behavior.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

This section presents a reusable pattern for exporting traces to ${process.env.GALILEO_CONSOLE_URL}/api/otel/v1/traces with a bearer token from GALILEO_API_KEY. Because the documentation instructs users to enable ongoing telemetry export, it should explicitly warn about the privacy/system-integrity implications of sending trace data externally.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.