Back to skill

Security audit

Boss Report

Security checks for vulnerabilities and agentic risk

Overview

The skill has a legitimate reporting purpose, but it tells the agent to gather broad private work, memory, session, and system data and persist/export it without clear user approval or redaction controls.

Review carefully before installing. Use it only for explicitly requested reports, restrict it to selected projects and date ranges, avoid session transcripts and long-term memory unless necessary, redact secrets and personal data, preview the report before saving or sharing, and treat generated HTML/PDF files as sensitive.

Vulnerability Patterns
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
Findings (2)

T05 · Unauthorized Access and Privilege Escalation

Warning
Location
SKILL.md:31
Finding

Overbroad Collection and Persistence of Sensitive Agent and System Data

Content
View full analysis
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Error
Location
report-generator.js:13
Finding

Stored HTML and Script Injection Through Unescaped Report Fields

Content
View full analysis
${metrics.map(m => `
${m.value}
${m.label}
`).join('')} ` : ''; const sectionsHTML = sections ? sections.map(s => `

${s.title}

${s.content} `).join('') : ''; const html = ` ${title} — ${date} ``` ```javascript

${title}

${date}
${type} Report
${metricsHTML} ${sectionsHTML} ``` ### Technical Analysis The generator interpolates JSON-controlled values directly into an HTML document without context-appropriate escaping or sanitization. Affected values include: - `title` - `date` - `type` - `metrics[].value` - `metrics[].label` - `sections[].title` - `sections[].content` Scalar values can terminate their intended HTML elements and introduce arbitrary markup. More critically, `sections[].content` is inserted as raw HTML, allowing active elements and event-handler attributes to be included directly. For example, a malicious input document could contain: ```json { "title": "Quarterly Report", "date": "2026-09-16", "type": "Daily", "metrics": [], "sections": [ { "title": "Summary", "content": "" } ] } ``` The CLI accepts a caller-selected JSON file and writes the resulting document withou ...[truncated 2036 chars]
Remediation
View remediation
alert(1)` - `` - `` - Element-breaking payloads in `title`, `date`, and metric labels - Links using `javascript:` or attacker-controlled remote URLs 9. If rich HTML is intentionally supported, document the trust boundary and accept it only from explicitly trusted sources rather than transcript-derived or user-controlled report data. ]]>
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (5)

Missing User Warnings

High
Category
Not specified by scanner
Confidence
98% confidence
Finding

The skill is explicitly designed to generate manager-facing reports by collecting session transcripts, memory files, git history, container status, cron history, and workspace file changes, yet it provides no privacy boundaries or consent requirements. This creates a clear risk of exposing credentials, private notes, proprietary code details, operational metadata, or unrelated user activity in a report intended for onward sharing.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The trigger phrases include common workplace language like "report to boss," "work summary," and "daily report," which can easily match ordinary user requests and invoke the skill unexpectedly. Because this skill gathers and exports sensitive local data, accidental invocation materially increases the chance of over-collection and unintended disclosure.

Content

No source excerpt is available for this finding.

Ssd 3

Medium
Category
Not specified by scanner
Confidence
97% confidence
Finding

These instructions tell the agent to aggregate data from multiple sensitive local sources and transform it into a consolidated boss-facing report. Aggregation increases sensitivity because dispersed operational, personal, and historical data become a single easy-to-share disclosure artifact, potentially revealing far more than the user intended.

Content

No source excerpt is available for this finding.

Ssd 3

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

The skill instructs persistent storage in memory files and onward delivery as HTML/PDF attachments without any sensitivity classification, retention limits, or sharing controls. Persisting and exporting these reports can compound exposure by leaving sensitive summaries in long-term storage and creating portable files that are easy to redistribute beyond the original context.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
93% confidence
Finding

The generated document sets <html lang="en">, which forces an English locale in the output regardless of the user's language or report content. This is a natural-language policy concern because the file does not offer a language choice or explain why English is required.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.