Back to skill

Security audit

Runa

Security checks for vulnerabilities and agentic risk

Overview

This skill does what it claims: it connects to Runa to save and manage bookmarks, notes, and uploaded files, with no hidden local persistence or unrelated behavior found.

Install this only if you intend your selected URLs, notes, and uploaded PDFs/images to be sent to Runa, stored in your Runa account, and in some cases enriched or AI-processed. Avoid saving secrets or confidential documents unless Runa is an approved place for that data, and review delete actions carefully because the API documentation says deletion is permanent.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Tool MisuseTool Parameter Abuse, Chaining Abuse, Unsafe Defaults
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
Findings (19)

Tool Parameter Abuse

High
Category
Tool Misuse
Confidence
80% confidence
Finding

Tool parameters are crafted to achieve unintended or unsafe behavior. Parameter abuse can bypass intended safety checks (e.g. shell=True, --force, dangerous glob patterns).

Content

Scanner excerpt · references/api.md (reported line 146)May include surrounding context.

md
---

## DELETE /v1/links/:id

Permanently delete a bookmark and its tags.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

The trigger phrases are broad enough that the skill could activate on common language like 'save this' or 'find my saved', causing accidental transmission, modification, or deletion of user data in an external system. Because the skill can write, update, delete, and upload, overbroad invocation scope meaningfully raises the chance of unintended sensitive actions.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The skill description does not clearly warn that user-provided text, URLs, and uploaded files are sent to a third-party service for storage and enrichment. This undermines informed consent and can lead to unintended disclosure of sensitive notes, links, or documents.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

The skill explicitly instructs the agent to read credentials from a local secrets file and environment variable. While using an API key is expected for this integration, directing the agent to access local secret material expands its credential-access capability and increases the blast radius if the skill is invoked unexpectedly or abused.

Content

No source excerpt is available for this finding.

External Transmission

Medium
Category
Data Exfiltration
Confidence
60% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · SKILL.md (reported line 26)May include surrounding context.

Save a bookmark

bash
curl -s -X POST https://api.onruna.com/v1/links \
  -H "Authorization: Bearer $RUNA_API_KEY" \
  -H "Content-Type: application/json" \
  -d '{"url": "<URL>"}'

External Transmission

Medium
Category
Data Exfiltration
Confidence
50% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · SKILL.md (reported line 26)May include surrounding context.

Save a bookmark

bash
curl -s -X POST https://api.onruna.com/v1/links \
  -H "Authorization: Bearer $RUNA_API_KEY" \
  -H "Content-Type: application/json" \
  -d '{"url": "<URL>"}'

External Transmission

Medium
Category
Data Exfiltration
Confidence
50% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · SKILL.md (reported line 44)May include surrounding context.

Save a bookmark

bash
curl -s -X POST https://api.onruna.com/v1/links \
  -H "Authorization: Bearer $RUNA_API_KEY" \
  -H "Content-Type: application/json" \
  -d '{"url": "<URL>"}'

External Transmission

Medium
Category
Data Exfiltration
Confidence
50% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · SKILL.md (reported line 53)May include surrounding context.

Save a bookmark

bash
curl -s -X POST https://api.onruna.com/v1/links \
  -H "Authorization: Bearer $RUNA_API_KEY" \
  -H "Content-Type: application/json" \
  -d '{"url": "<URL>"}'

External Transmission

Medium
Category
Data Exfiltration
Confidence
50% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · SKILL.md (reported line 77)May include surrounding context.

Save a bookmark

bash
curl -s -X POST https://api.onruna.com/v1/links \
  -H "Authorization: Bearer $RUNA_API_KEY" \
  -H "Content-Type: application/json" \
  -d '{"url": "<URL>"}'

External Transmission

Medium
Category
Data Exfiltration
Confidence
50% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · SKILL.md (reported line 92)May include surrounding context.

Save a bookmark

bash
curl -s -X POST https://api.onruna.com/v1/links \
  -H "Authorization: Bearer $RUNA_API_KEY" \
  -H "Content-Type: application/json" \
  -d '{"url": "<URL>"}'

External Transmission

Medium
Category
Data Exfiltration
Confidence
87% confidence
Finding

The endpoint use here is tied to saving arbitrary text to a third-party service, which carries meaningful privacy risk because users may paste sensitive notes or credentials. The context makes this more dangerous than generic outbound traffic because enrichment and storage are persistent and involve potentially high-sensitivity free text.

Content

Scanner excerpt · SKILL.md (reported line 35)May include surrounding context.

Save text

bash
curl -s -X POST https://api.onruna.com/v1/links \
  -H "Authorization: Bearer $RUNA_API_KEY" \
  -H "Content-Type: application/json" \
  -d '{"text": "Some text content to save"}'

External Transmission

Medium
Category
Data Exfiltration
Confidence
87% confidence
Finding

The endpoint use here is tied to saving arbitrary text to a third-party service, which carries meaningful privacy risk because users may paste sensitive notes or credentials. The context makes this more dangerous than generic outbound traffic because enrichment and storage are persistent and involve potentially high-sensitivity free text.

Content

Scanner excerpt · SKILL.md (reported line 35)May include surrounding context.

Save text

bash
curl -s -X POST https://api.onruna.com/v1/links \
  -H "Authorization: Bearer $RUNA_API_KEY" \
  -H "Content-Type: application/json" \
  -d '{"text": "Some text content to save"}'

External Transmission

Medium
Category
Data Exfiltration
Confidence
60% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · SKILL.md (reported line 77)May include surrounding context.

Get a single bookmark

bash
curl -s "https://api.onruna.com/v1/links/<id>" \
  -H "Authorization: Bearer $RUNA_API_KEY"

External Transmission

Medium
Category
Data Exfiltration
Confidence
71% confidence
Finding

Updating remote bookmark metadata/status is expected, but it is a mutating external action and the rules only require confirmation for deletion, not other writes. In combination with broad triggers, this increases the risk of unintended changes to user data stored in the third-party service.

Content

Scanner excerpt · SKILL.md (reported line 83)May include surrounding context.

Update a bookmark

bash
curl -s -X PATCH "https://api.onruna.com/v1/links/<id>" \
  -H "Authorization: Bearer $RUNA_API_KEY" \
  -H "Content-Type: application/json" \
  -d '{"status": "archived"}'

External Transmission

Medium
Category
Data Exfiltration
Confidence
83% confidence
Finding

The enrich-preview feature sends a URL to a third-party service even when the user may think they are only previewing content locally. Because this capability is omitted from the manifest, users may not understand that merely asking for a preview still transmits data externally.

Content

Scanner excerpt · SKILL.md (reported line 98)May include surrounding context.

Enrich a URL (preview without saving)

bash
curl -s -X POST https://api.onruna.com/v1/enrich \
  -H "Authorization: Bearer $RUNA_API_KEY" \
  -H "Content-Type: application/json" \
  -d '{"url": "<URL>"}'

External Transmission

Medium
Category
Data Exfiltration
Confidence
94% confidence
Finding

Uploading files to an external service creates substantial confidentiality risk because PDFs and images may contain personal, proprietary, or regulated data. The skill description does not prominently warn users that uploaded documents are transmitted and stored remotely, making accidental sensitive-data disclosure more likely.

Content

Scanner excerpt · SKILL.md (reported line 106)May include surrounding context.

Upload a file (PDF or image)

bash
curl -s -X POST https://api.onruna.com/v1/files \
  -H "Authorization: Bearer $RUNA_API_KEY" \
  -F "file=@/path/to/file.pdf"

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
86% confidence
Finding

This markdown file documents multiple endpoints that send URLs, text content, and uploaded files to a remote API for enrichment, storage, AI tagging, and background processing, but it does not include any warning about privacy or data-handling implications. Because the file is a markdown document and these behaviors can affect user data and system privacy, the omission fits the missing-warning criterion.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
90% confidence
Finding

The DELETE endpoint states that it will permanently delete a bookmark and its tags, but the documentation provides no explicit warning or caution callout about irreversibility. For markdown files, destructive behaviors that can affect user data should be accompanied by a user-facing warning.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

Low
Category
Not specified by scanner
Confidence
88% confidence
Finding

The manifest scopes the skill to saving, searching, listing, updating, deleting bookmarks/notes, and uploading files. The instructions also include POST /v1/enrich to fetch preview/enrichment data without saving, which is a distinct behavior not reflected in the manifest description or trigger guidance.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.