Back to skill

Security audit

Venice

Security checks for vulnerabilities and agentic risk

Overview

This Venice travel skill is mostly a normal travel guide, but it includes a persistent memory template field for a password, which is not needed for trip planning.

Review this skill before installing. Its travel-guide content is ordinary, but do not let it store passwords, booking portal credentials, Wi-Fi passwords, API keys, or other secrets in memory.md; remove or ignore that field and keep saved trip memory limited to non-sensitive travel preferences and confirmations.

Vulnerability Patterns
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (1)

T09 · Insecure Skill Coding Practices

Warning
Location
memory-template.md:57
Finding
Plaintext Password Storage in Persistent Trip Memory## Vulnerability Details **File Location**: `memory-template.md:57` **Vulnerability Type**: Plaintext sensitive-data storage **Risk Level**: Medium ### Vulnerable Code ```markdown ## Useful Info Saved - **Preview password preview:** - **Restaurant recommendations:** - **Local tips received:** ``` ### Technical Analysis The memory template provides a field for recording a password. `SKILL.md` describes the resulting `memory.md` file as persistent trip state, meaning a password entered into this field could be retained in plaintext across sessions. Password storage is not necessary for the Skill's stated Venice travel-guidance purpose. The project specifies no encryption, redaction, access restrictions, expiration policy, or integration with an approved secret manager. Consequently, a stored password could be exposed through workspace access, backups, synchronization, logs, or later Agent context retrieval. This is an insecure coding and configuration practice rather than evidence of deliberate credential theft. No mechanism was found that automatically collects or transmits the stored value. ### Attack Path 1. A user, host, travel document, or other input provides a password, such as an accommodation or Wi-Fi credential. 2. The Agent records that value in the password field when creating or updating `memory.md`. 3. The password remains available as plaintext in persistent project state. 4. Another user, process, backup system, synchronization service, or later Agent session with access to the workspace reads the stored value. 5. If the credential remains valid, the reader may use it to access the service it protects. Credential reuse could increase the impact beyond the original service. ### Impact Assessment Exploitation does not directly grant operating-system privileges or execute code. The immediate impact is loss of confidentiality for any password stored in the field. The practical access obtained depen ...[truncated 355 chars]
Remediation
## Remediation Suggestions 1. Remove the password field from `memory-template.md`. 2. Store only a non-sensitive reference, such as “Credential available from host,” rather than the credential itself. 3. If retention is unavoidable, use an approved secret manager or operating-system credential store instead of Markdown memory. 4. Prevent secrets from entering prompts, logs, backups, synchronization systems, and long-term Agent context. 5. Apply least-privilege access controls and explicit retention limits to persistent trip data. 6. Add validation and redaction rules for password-like values, API tokens, authentication cookies, recovery codes, and other credentials. 7. Review existing generated `memory.md` files and securely remove any credentials already stored there. Rotate exposed credentials where appropriate.
Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
Findings (14)

Ae1

High
Category
analysis-evasion
Content
| Overview & dining scene | `food-overview.md` |
Confidence
100% confidence
Finding
Referenced artifact was not completely inspected

Ae1

High
Category
analysis-evasion
Content
| Practical (reservations, tourist traps) | `food-practical.md` |
Confidence
100% confidence
Finding
Referenced artifact was not completely inspected

Ae1

High
Category
analysis-evasion
Content
| Practical (reservations, tourist traps) | `food-practical.md` |
Confidence
100% confidence
Finding
Referenced artifact was not completely inspected

Ae1

High
Category
analysis-evasion
Content
| Cost of living & visiting | `cost.md` |
Confidence
100% confidence
Finding
Referenced artifact was not completely inspected

Ae1

High
Category
analysis-evasion
Content
| Safety & scams | `safety.md` |
Confidence
100% confidence
Finding
Referenced artifact was not completely inspected

Ae1

High
Category
analysis-evasion
Content
| Safety & scams | `safety.md` |
Confidence
100% confidence
Finding
Referenced artifact was not completely inspected

Anti-Refusal Statement

High
Category
Anti-Refusal
Content
### Must-Haves
- **Comfortable walking shoes** — You'll walk 10-20 km/day on stone
- **Layers** — Temperature varies, churches are cold
- **Compact umbrella** — Rain comes without warning
- **Reusable water bottle** — Fill at fountains
- **Small daypack** — Not big backpack (awkward on boats/crowds)
- **Portable charger** — For all that photo-taking
Confidence
80% confidence
Finding
Skill instructs the agent to omit warnings, disclaimers, or ethical commentary. Stripping safety caveats hides risk from the user and is a common jailbreak preamble.

Vague Triggers

Medium
Confidence
94% confidence
Finding
The invocation guidance says the skill should be used when a user asks about Venice 'for any purpose,' including broad activities like understanding the city or exploring culture. This lacks clear boundaries or exclusion conditions, making unintended activation likely for casual or tangential mentions of Venice.

Context-Inappropriate Capability

Medium
Confidence
98% confidence
Finding
The template includes a field labeled for storing a password preview, which is unrelated to a Venice travel-planning skill and can encourage collection or retention of credential-like sensitive data in long-term memory. In this context, there is no legitimate functional need for password handling, so the field increases the risk of accidental secret capture, leakage to later prompts, or exposure through logs and memory synchronization.

Missing User Warnings

Low
Confidence
89% confidence
Finding
This markdown file describes a 'bacaro crawl' with multiple wine stops and explicitly recommends 3-6 drinks over a short period, but it provides no caution about alcohol consumption, intoxication, or suitability for minors, drivers, or others who should avoid drinking. For markdown files, omitted warnings about behaviors that could affect user safety fall under missing user warnings.

Natural-Language Policy Violations

Low
Confidence
82% confidence
Finding
This markdown file includes natural-language guidance that treats 'Menu in Italian only' as a green flag. That favors a specific language/locale without offering user choice or framing it as an optional heuristic, which matches the language/locale policy concern.

Natural-Language Policy Violations

Low
Confidence
94% confidence
Finding
The instruction 'Book in Italian if possible' explicitly directs users to use a particular language. Because it does not offer a language choice or explain a justified regional compliance need, it is a natural-language locale policy violation under the stated rule.

Natural-Language Policy Violations

Low
Confidence
87% confidence
Finding
This natural-language statement treats Italian-only menus as inherently preferable, implicitly privileging one language rather than offering language choice. Under the language/locale policy, content should not force or endorse a specific language expectation without user opt-in or clear justification.

Natural-Language Policy Violations

Low
Confidence
6% confidence
Finding
After review, the file is a travel guide in markdown and does not instruct the user to use a specific language or locale against their preference. References to Venice-specific prices, transit lines, and local sites are contextually appropriate for the subject matter rather than a forced locale policy.

Static analysis

No suspicious patterns detected.