Back to skill

Security audit

Client Onboarding Automator

Security checks for vulnerabilities and agentic risk

Overview

The skill is a coherent onboarding automator, but it includes unsafe credential emailing and broad no-manual-step automation for contracts, payments, and client communications.

Review this skill carefully before installing. Do not use it to email passwords, API keys, or reusable credentials; replace that step with secure account invitations or one-time activation links. Add explicit human review before sending contracts, payment links, CRM updates, or scheduled client emails, and define how client data is collected, stored, shared, and deleted.

Vulnerability Patterns
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (1)

T09 · Insecure Skill Coding Practices

Warning
Location
SKILL.md:67
Finding

Reusable Access Credentials Sent Through Email

Content
View full analysis

Vulnerability Details

File Location: SKILL.md, line 67
Vulnerability Type: Plaintext transmission of sensitive authentication data
Risk Level: Medium

Vulnerable Code Snippet:

markdown
- **Day 0:** Welcome email + access credentials + kickoff questionnaire

Technical Analysis

The documented onboarding workflow explicitly instructs the agent to include access credentials in a welcome email. Conventional email does not provide a suitable end-to-end secret-delivery mechanism. Credential-bearing messages can persist in sender and recipient mailboxes, email-provider storage, backups, forwarding chains, notification previews, and mail-processing logs.

The workflow does not require the credentials to be single-use, time-limited, encrypted for the intended recipient, or invalidated after first use. It also does not require a forced password reset or multifactor authentication. Consequently, anyone who obtains the message may be able to reuse the credentials.

Attack Path

  1. The onboarding workflow creates or obtains credentials for a client resource.
  2. The agent sends those credentials in the Day 0 welcome email.
  3. The message is retained in one or more mail systems or is forwarded to another account.
  4. An attacker gains access to the recipient's mailbox, a forwarded copy, an email archive, or exposed mail-processing records.
  5. The attacker extracts the reusable credentials.
  6. The attacker authenticates to the associated account or project resource before the credentials are revoked.

Impact Assessment

Successful exploitation could permit unauthorized access with the privileges assigned to the exposed client account. Depending on the destination system, this may expose client documents, project data, communications, or account functionality. The precise scope is not defined by the repository and therefore depends on the permissions granted to the transmitted credentials.

Remediation
View remediation

Remediation Suggestions

  • Do not send passwords, API keys, access tokens, or other reusable credentials through email.
  • Replace credential delivery with a cryptographically random, single-use account-activation link.
  • Apply a short expiration period to the activation token and invalidate it immediately after use.
  • Bind activation to the intended account and prevent token reuse.
  • Require the client to establish their own password through a secure HTTPS page.
  • Enforce multifactor authentication where supported.
  • Avoid placing activation tokens in email subject lines or analytics-enabled links, and redact them from application and proxy logs.
  • Revoke any provisioned credential if activation is not completed within the permitted period.
  • Add documented recovery and immediate revocation procedures for misdirected or compromised onboarding messages.
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (4)

Missing User Warnings

High
Category
Not specified by scanner
Confidence
97% confidence
Finding

Including 'access credentials' in an automated welcome email is security-sensitive because email is not a safe channel for transmitting secrets and is commonly exposed through inbox compromise, forwarding, or misdelivery. The skill normalizes secret distribution without warning or safeguards, which can directly lead to account takeover or unauthorized access to client resources.

Content

No source excerpt is available for this finding.

Credential Access

High
Category
Privilege Escalation
Confidence
98% confidence
Finding

The explicit instruction to send 'access credentials' indicates handling and transmission of authentication secrets. In this context, the skill is not merely referencing credentials academically; it operationalizes their delivery in a real client workflow, making exposure through email interception, mailbox compromise, logging, or accidental reuse a realistic risk.

Content

Scanner excerpt · SKILL.md (reported line 67)May include surrounding context.

md
### Step 5: Welcome Sequence
After payment:
- **Day 0:** Welcome email + access credentials + kickoff questionnaire
- **Day 1:** "Getting started" guide + calendar link for kickoff call
- **Day 3:** Check-in + first deliverable preview
- **Day 7:** Progress update + feedback request

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The skill is designed to collect, process, and transmit client personal data and initiate payment-related actions, but it provides no privacy notice, consent controls, data-minimization guidance, or operator warning about handling sensitive information. In an onboarding workflow, this increases the risk of unauthorized processing, over-collection, accidental disclosure, and compliance failures, especially when email, CRM, contracts, and payment systems are linked automatically.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
89% confidence
Finding

The description advertises end-to-end automation for intake processing, contract generation, payment collection, email sequencing, and project setup with 'zero manual steps,' but provides no trigger boundaries, approval gates, or scope constraints. In an agent ecosystem, such broad wording can cause over-activation or unsafe invocation across sensitive business workflows involving contracts, billing, and client communications.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.