Back to skill

Security audit

workflow-migrate

Security checks for vulnerabilities and agentic risk

Overview

The skill is mostly a workflow-migration template, but it bakes in person-specific Kevin assumptions and a fixed Telegram chat ID that could send workflow failure details to an unintended recipient.

Review carefully before installing. Remove Kevin-specific instructions, remove the fixed TELEGRAM_CHAT_ID, make external alerts explicitly opt-in to a user-owned destination, and redact or avoid payload logging before using this to migrate workflows that handle business data, customer data, or secrets.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (2)

T01 · Skill Instruction Hijacking

Error
Location
SKILL.md:218
Finding

Hard-Coded Third-Party Telegram Recipient Enables Unauthorized Error-Data Disclosure

Content
View full analysis
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Warning
Location
SKILL.md:132
Finding

Dry-Run Templates Persist Complete HTTP Request Payloads in Logs

Content
View full analysis
Remediation
View remediation
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (9)

Credential Access

High
Category
Privilege Escalation
Confidence
60% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · SKILL.md (reported line 117)May include surrounding context.

md
log = logging.getLogger(__name__)

# ─── Config ────────────────────────────────────────────────────────────────────
API_KEY = os.getenv("API_KEY")         # from .env
WEBHOOK_URL = os.getenv("WEBHOOK_URL") # destination
DRY_RUN = False

Credential Access

High
Category
Privilege Escalation
Confidence
60% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · SKILL.md (reported line 234)May include surrounding context.

md
log = logging.getLogger(__name__)

# ─── Config ────────────────────────────────────────────────────────────────────
API_KEY = os.getenv("API_KEY")         # from .env
WEBHOOK_URL = os.getenv("WEBHOOK_URL") # destination
DRY_RUN = False

Credential Access

High
Category
Privilege Escalation
Confidence
60% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · SKILL.md (reported line 310)May include surrounding context.

md
log = logging.getLogger(__name__)

# ─── Config ────────────────────────────────────────────────────────────────────
API_KEY = os.getenv("API_KEY")         # from .env
WEBHOOK_URL = os.getenv("WEBHOOK_URL") # destination
DRY_RUN = False

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 275)May include surrounding context.

md
- Generate a `SKILL.md` in the same output directory

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 290)May include surrounding context.

md
- Generate a `SKILL.md` in the same output directory

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
88% confidence
Finding

The skill hard-codes 'Kevin' as the request authority for language choice, embedding a person-specific operational assumption into a reusable automation tool. While not directly exploitable on its own, this can misroute decisions, normalize recipient-specific behavior, and contributes to unsafe user-context confusion in generated outputs.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

The skill instructs generated workflows to send failure alerts using a hard-coded Telegram destination tied to a specific person/context ('Kevin's bot token if available'). That introduces an unnecessary outbound communication path and can cause operational data, error details, or sensitive metadata to be exfiltrated to an unintended third party during failures.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The same line that defines failure alerts also bakes in person-specific organizational context ('Kevin's bot token'), which increases the risk that generated workflows inherit hidden routing assumptions for secrets and notifications. In an automation-migration skill, that context is unjustified and can lead to unauthorized disclosure of runtime errors or business data.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

Medium
Category
Not specified by scanner
Confidence
98% confidence
Finding

Embedding a specific Telegram chat ID in .env.example seeds generated projects with a recipient-controlled messaging channel that is unrelated to core workflow migration. If the generated script later enables alerts, failures or runtime data may be sent to that fixed external recipient without the user's informed consent.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.