Back to skill

Security audit

workbuddy-skill-session-callback

Security checks for vulnerabilities and agentic risk

Overview

This skill openly enables high-impact WorkBuddy cross-session message injection, but it lacks hard authorization controls and its script can send callback data to arbitrary endpoints despite loopback-only claims.

Install only if you specifically need WorkBuddy Desktop session-to-session callbacks and are comfortable with one session or automation waking another with its full context. Do not inject untrusted external input, avoid remote or non-loopback --endpoint values, use fixed target-session allowlists where possible, label callback messages as external notifications, require confirmation before sensitive actions, and remove temporary automations after use.

Vulnerability Patterns
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
Findings (2)

T05 · Unauthorized Access and Privilege Escalation

Error
Location
scripts/callback.py:137
Finding

Unauthenticated Cross-Session Prompt Injection

Content
View full analysis
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Error
Location
scripts/callback.py:100
Finding

Arbitrary Network Endpoint Permitted Despite Loopback-Only Security Claims

Content
View full analysis
Remediation
View remediation
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Rogue AgentSelf-Modification, Session Persistence
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
Findings (10)

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
91% confidence
Finding

The skill explicitly instructs reading local session registry/transcript files and making HTTP requests to local ACP endpoints, but it declares no tool scope or permission boundaries. Because this skill enables cross-session message injection into other agent sessions, the missing explicit restrictions increase the chance that an agent or user invokes sensitive file and network actions without clear guardrails or review.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The documentation explicitly enables injecting arbitrary user messages into another active session and confirms that the target agent will continue with its full prior context. Because loopback requests are exempt from authentication and the feature is framed as a general callback mechanism, this creates a real cross-session integrity and privacy risk: any local process able to reach the endpoint can steer another session, trigger actions, or cause unintended disclosure from that session’s retained context. The absence of strong warnings, consent requirements, or scope restrictions makes misuse substantially more likely.

Content

No source excerpt is available for this finding.

Session Persistence

Medium
Category
Rogue Agent
Confidence
65% confidence
Finding

Skill establishes unauthorized persistence across sessions via cron jobs, startup scripts, or state files. Session persistence allows an attacker to maintain access beyond the current interaction.

Content

Scanner excerpt · README.md (reported line 123)May include surrounding context.

md
## 定时调度

- 可靠调度:WorkBuddy 内置 automation(宿主进程调度,独立于 agent 回合)
- 不可靠:nohup / Start-Process 后台进程(随 agent 回合结束被回收)

Session Persistence

Medium
Category
Rogue Agent
Confidence
65% confidence
Finding

Skill establishes unauthorized persistence across sessions via cron jobs, startup scripts, or state files. Session persistence allows an attacker to maintain access beyond the current interaction.

Content

Scanner excerpt · SKILL.md (reported line 103)May include surrounding context.

md
## 定时调度

- 可靠调度:WorkBuddy 内置 automation(宿主进程调度,独立于 agent 回合)
- 不可靠:nohup / Start-Process 后台进程(随 agent 回合结束被回收)

Session Persistence

Medium
Category
Rogue Agent
Confidence
65% confidence
Finding

Skill establishes unauthorized persistence across sessions via cron jobs, startup scripts, or state files. Session persistence allows an attacker to maintain access beyond the current interaction.

Content

Scanner excerpt · references/api_reference.md (reported line 80)May include surrounding context.

md
## 定时调度

- 可靠调度:WorkBuddy 内置 automation(宿主进程调度,独立于 agent 回合)
- 不可靠:nohup / Start-Process 后台进程(随 agent 回合结束被回收)

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
98% confidence
Finding

The header comment documents an unauthenticated loopback flow that obtains connectionId and sessionToken from local ACP endpoints and then loads and prompts arbitrary sessions. Even if intended for localhost use, this creates a trust boundary bypass: any local code able to reach the endpoint and discover session metadata may impersonate a client and manipulate agent state without meaningful authentication or user awareness.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The script explicitly injects arbitrary user-controlled text into another live session via session/prompt, causing the target agent to resume with its full prior context and potentially take actions in that session. This is a cross-session state modification primitive with no confirmation, authorization gate, or warning, so a local process, cron job, or another session can silently steer a different agent thread and trigger unintended actions.

Content

No source excerpt is available for this finding.

Vague Triggers

Low
Category
Not specified by scanner
Confidence
82% confidence
Finding

This manifest description says the skill enables one session, external process, cron job, or another session to inject messages and wake a target agent, but it does not describe concrete activation boundaries or exclusion conditions. In a manifest file, this broad wording can make it unclear when the skill should be invoked versus when similar automation or messaging tasks should not use it.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
71% confidence
Finding

The manifest description is written entirely in Chinese and does not indicate that other languages are supported or that the language is a user-selectable preference. This can be a natural-language policy concern if the skill is expected to be usable in multiple locales without forcing a specific language.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
94% confidence
Finding

The user-facing docstring and CLI help text are written in Chinese only, which imposes a language choice on users without opt-in or explanation. Under the language/locale policy, forcing a specific language without offering a choice or documenting a justified regional constraint is a policy concern.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.