Back to skill

Security audit

External Ki Integration Backup

Security checks for vulnerabilities and agentic risk

Overview

This skill is a mostly coherent external AI connector, but it asks to use logged-in third-party AI sessions/APIs and to persist interactions without enough scoping or consent controls.

Install only if you intentionally want agents to send selected prompts or content to external AI services using your logged-in browser sessions or API keys. Avoid using it with confidential, personal, financial, credential, or proprietary data unless you explicitly approve the exact data being shared, and disable or restrict any memory logging of prompts and responses.

Vulnerability Patterns
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Findings (1)

T02 · Agent Memory Poisoning

Warning
Location
SKILL.md:160
Finding

Persistent Storage of Untrusted External AI Content

Content
View full analysis

Vulnerability Details

File Location: SKILL.md, line 160
Vulnerability Type: Agent Memory Poisoning
Risk Level: Medium

Vulnerable Code Snippet:

markdown
8. **Log** the interaction in memory (pattern learned).

Technical Analysis

The skill directs the agent to persist an interaction with an external AI service as a learned memory pattern. External model output is untrusted content: it may be influenced by malicious prompts, compromised upstream content, prompt injection, or unreliable model-generated instructions.

No validation, sanitization, provenance tracking, content restrictions, user approval, expiration policy, or isolation boundary is required before this information is written to persistent memory. Consequently, attacker-controlled instructions or misleading behavioral patterns could be retained and treated as trusted guidance in later sessions.

Attack Path

  1. An attacker influences a prompt, external AI response, or content processed by the external service.
  2. The external model returns adversarial instructions or a deliberately misleading behavioral pattern.
  3. The agent follows the workflow in SKILL.md and records the interaction as a learned memory pattern.
  4. The stored content persists beyond the current task.
  5. In a later session, the agent retrieves or relies on the poisoned memory.
  6. The malicious pattern influences future decisions, tool usage, or handling of user data.

Impact Assessment

Successful exploitation may affect future sessions that consume the poisoned memory. An attacker could influence subsequent agent reasoning or actions within the privileges already available to the agent, including its permitted tools and accessible data.

This instruction does not independently grant additional operating-system privileges or establish a system-level backdoor. Its impact is limited by the agent's existing permissions and whether the stored memory is late ...[truncated 185 chars]

Remediation
View remediation

Remediation Suggestions

  1. Remove automatic or unconditional memory logging from the workflow.
  2. Require explicit user approval before persisting any information beyond the current task.
  3. Store only a concise, factual, sanitized summary rather than complete prompts, responses, or executable instructions.
  4. Reject external content that attempts to define future agent behavior, alter safety controls, invoke tools, or override trusted instructions.
  5. Redact credentials, API keys, personal data, confidential information, and session identifiers before storage.
  6. Record provenance, creation time, task scope, and trust level for retained information.
  7. Apply expiration and deletion policies so task-specific records do not remain indefinitely.
  8. Isolate externally derived notes from trusted operational instructions and require review before promoting any content into reusable memory.
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
Findings (6)

Missing User Warnings

High
Category
Not specified by scanner
Confidence
97% confidence
Finding

The skill's core purpose is to send user prompts and extracted content to external AI services, but it does not prominently warn that task data may leave the platform during normal operation. This lack of explicit disclosure undermines informed consent and can expose sensitive or proprietary information to third parties and their retention policies.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The activation criteria are broad enough to trigger this skill for generic reasoning, analysis, coding, summarization, and 'second opinion' tasks. Because this skill routes content to third-party services, overbroad invocation increases the chance that ordinary user content is unnecessarily sent off-platform without a narrowly scoped need.

Content

No source excerpt is available for this finding.

External Transmission

Medium
Category
Data Exfiltration
Confidence
78% confidence
Finding

The direct reference to the OpenAI endpoint indicates a concrete off-platform destination for task data, confirming that the skill enables external transmission. While expected for this integration skill, it remains a genuine risk because broad activation plus weak disclosure can cause unnecessary sharing of user content with a third party.

Content

Scanner excerpt · SKILL.md (reported line 95)May include surrounding context.

If user provides an API key, you can call models via curl or exec:

bash
curl -s -X POST https://api.openai.com/v1/chat/completions \
  -H "Authorization: Bearer $OPENAI_API_KEY" \
  -H "Content-Type: application/json" \
  -d '{

External Transmission

Medium
Category
Data Exfiltration
Confidence
78% confidence
Finding

The direct reference to the OpenAI endpoint indicates a concrete off-platform destination for task data, confirming that the skill enables external transmission. While expected for this integration skill, it remains a genuine risk because broad activation plus weak disclosure can cause unnecessary sharing of user content with a third party.

Content

Scanner excerpt · SKILL.md (reported line 95)May include surrounding context.

If user provides an API key, you can call models via curl or exec:

bash
curl -s -X POST https://api.openai.com/v1/chat/completions \
  -H "Authorization: Bearer $OPENAI_API_KEY" \
  -H "Content-Type: application/json" \
  -d '{

External Transmission

Medium
Category
Data Exfiltration
Confidence
81% confidence
Finding

This section provides a concrete example of transmitting content to Anthropic's API, so the external transmission finding is valid. The danger is contextual rather than inherently malicious: the skill is designed for this purpose, but without strong consent and handling rules it can expose sensitive content and generate paid usage.

Content

Scanner excerpt · SKILL.md (reported line 106)May include surrounding context.

Anthropic Claude

bash
curl -s -X POST https://api.anthropic.com/v1/messages \
  -H "x-api-key: $ANTHROPIC_API_KEY" \
  -H "anthropic-version: 2023-06-01" \
  -H "Content-Type: application/json" \

Context-Inappropriate Capability

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The skill instructs the agent to log external AI interactions into memory even though persistence is not necessary to perform the stated function of querying external services. This creates an avoidable data retention risk because prompts, responses, or user-provided content may contain sensitive information that then becomes stored beyond the immediate task lifecycle.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.