Back to skill

Security audit

consensus-send-email-guard

Security checks for vulnerabilities and agentic risk

Overview

This email-approval guard is purpose-aligned, but trust and validation gaps could let unsafe emails receive authoritative-looking approvals.

Review before installing in any real outbound-email workflow. Treat decisions as advisory unless constraints come from trusted configuration, external_agent mode is limited to authenticated trusted voters, reputation weights are derived from board state, and dependencies are pinned and updated. Use a dedicated non-privileged state directory and do not let untrusted callers control guard settings or vote payloads.

Vulnerability Patterns
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (2)

T09 · Insecure Skill Coding Practices

Error
Location
src/llm.mjs:8
Finding

Mandatory hard-block controls can be disabled by omitting caller-supplied constraints

Content
View full analysis
Remediation
View remediation
0) { return { final_decision: 'BLOCK', hard_block: true, red_flags: mandatoryFlags }; } ``` 7. If policy customization is required, load it from trusted board configuration rather than accepting security-disable switches from the email submitter. 8. Add regression tests proving that sensitive data and prohibited claims are blocked when constraints are missing, incomplete, or explicitly false. ]]>

T09 · Insecure Skill Coding Practices

Error
Location
src/validate.mjs:34
Finding

Untrusted external votes and reputation weights can forge or corrupt governance decisions

Content
View full analysis
/threat|harass|doxx|sensitive|legal_claim|medical_claim|wrongdoing|confidential/i.test(f))) { hard_block = true; } } ``` ### Technical Analysis In `external_agent` mode, the caller controls every security-critical property used by the aggregation algorithm: - The selected vote. - The reputation weight. - The presence or absence of hard-block red flags. - Persona identity fields, which are not authenticated or checked. - The number of votes submitted. The implementation does not ...[truncated 3098 chars]
Remediation
View remediation
0.95) { return 'external_votes.reputation_before must be finite and between 0.05 and 0.95'; } ``` 7. Reject vote collections whose total trusted weight is not finite and strictly positive. 8. Validate `red_flags` as an array of recognized enumerated values, but do not rely on caller-submitted red flags for mandatory controls. 9. Run mandatory hard-block detection directly against the email draft before aggregating external votes. 10. Verify that each authorized voter appears at most once. 11. Use a trusted persona set or voter registry and reject unknown persona IDs. 12. Add tests for: - Empty vote arrays. - Negative, zero, excessive, `NaN`, and infinite weights in direct API use. - Duplicate voter identities. - Unsigned or unauthorized votes. - Unsafe content paired with forged `YES` votes. - Vote totals that are zero or non-finite. ]]>
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Findings (6)

Natural-Language Policy Violations

High
Category
Not specified by scanner
Confidence
98% confidence
Finding

The example input explicitly asks the recipient to share confidential account details while the declared constraints forbid sensitive data. In a skill designed to govern outbound email and produce machine-parseable approve/block decisions, shipping contradictory example content can normalize unsafe prompts, weaken downstream policy testing, and cause implementations or evaluators to mishandle sensitive-data exfiltration scenarios.

Content

No source excerpt is available for this finding.

Known Vulnerable Dependency: fast-uri==3.1.0 — 7 advisory(ies): CVE-2026-13676 (fast-uri vulnerable to host confusion via failed IDN canonicalization); CVE-2026-18446 (fast-uri vulnerable to host confusion via backslash authority introducer); CVE-2026-75975 (fast-uri vulnerable to server-side request forgery via malformed IPv6 normalizat) +4 more

High
Category
Supply Chain
Confidence
93% confidence
Finding

fast-uri 3.1.0 is a real vulnerable dependency, and the cited issues involve URI/host parsing confusion that can undermine hostname validation and enable SSRF or policy bypass. In this skill's context—email governance and decision/ledger tooling—dependency-driven URL parsing flaws are more concerning because agent ecosystems often ingest untrusted configuration, webhook, board, or service endpoints, so a parsing discrepancy could redirect internal requests or bypass allowlists.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
89% confidence
Finding

The writeArtifact function initializes storage and posts, submits, and resolves jobs that persist artifact data to the backing JsonStorage, but there is no confirmation prompt, user-visible log/print, or explanatory comment/docstring warning that state will be modified. This is a safety-relevant file write/persistence operation and the code itself provides no disclosure.

Content

No source excerpt is available for this finding.

Known Vulnerable Dependency: esbuild==0.27.3 — 1 advisory(ies): GHSA-g7r4-m6w7-qqqr (esbuild allows arbitrary file read when running the development server on Window)

Low
Category
Supply Chain
Confidence
60% confidence
Finding

Dependency has known vulnerabilities (CVEs). Using packages with unpatched security flaws exposes the environment to known exploits.

Content

No source excerpt is available for this finding.

Unpinned Dependencies

Low
Category
Supply Chain
Confidence
88% confidence
Finding

The dependency uses a caret range, which allows npm to install newer compatible releases without explicit review. If an upstream package is compromised or introduces a breaking security change, the skill could consume that version during install, creating a supply-chain risk.

Content

Scanner excerpt · package.json (reported line 10)May include surrounding context.

json
"demo": "node --import tsx run.js --input ./examples/email-input.json"
  },
  "dependencies": {
    "consensus-guard-core": "^1.1.15",
    "tsx": "^4.20.3"
  },
  "license": "MIT",

Unpinned Dependencies

Low
Category
Supply Chain
Confidence
88% confidence
Finding

The tsx dependency is specified with a caret range, so future patch and minor releases may be pulled in automatically. This increases exposure to supply-chain compromise or unsafe upstream changes, especially because tsx is used to execute project code during test and demo flows.

Content

Scanner excerpt · package.json (reported line 11)May include surrounding context.

json
},
  "dependencies": {
    "consensus-guard-core": "^1.1.15",
    "tsx": "^4.20.3"
  },
  "license": "MIT",
  "engines": {

Static analysis

No suspicious patterns detected.