Back to skill

Security audit

Mission Control

Security checks for vulnerabilities and agentic risk

Overview

This task-board skill is not clearly malicious, but it handles powerful GitHub and local-agent access in ways users should review carefully before installing.

Review this before installing. Use it only with a private, trusted-user repository and a tightly restricted agent environment. Prefer fine-grained, single-repository GitHub tokens over classic repo-scope PATs, avoid storing gateway tokens in the browser, require signed webhooks with a configured secret, and do not expose the gateway or CORS proxy publicly without additional authentication and origin restrictions.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
Findings (5)

T01 · Skill Instruction Hijacking

Error
Location
assets/transforms/github-mission-control.mjs:215
Finding

Fail-Open Webhook Authentication Allows Untrusted Task Content to Control the Agent

Content
View full analysis
0) { lines.push(`**Subtasks:**`); for (const sub of fullTask.subtasks) { const check = sub.done ? '✅' : '⬜'; lines.push(`${check} ${sub.title}`); } } lines.push('Führe diese Aufgabe jetzt aus. Nach Abschluss: Ticket auf "Review" setzen und Ergebnis als Kommentar dokumentieren.'); ``` ```js const workOrder = formatWorkOrder(inProgressTasks, newTasks); log(`Waking agent for ${inProgressTasks.length} tasks`, config); await wakeAgent(workOrder, inProgressTask ...[truncated 2414 chars]
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Error
Location
assets/index.html:3741
Finding

Stored Cross-Site Scripting in GitHub-Sourced Task Rendering

Content
View full analysis
No tasks' : tasks.map(renderTaskCard).join(''); ``` ```js return `
${task.title} ${archivedBadge}
${processingIndicator}
${task.description}
${task.tags.map(tag => `${tag}`).join('')}
${commentIndicator}
`; ``` ```js container.innerHTML = task.subtasks.map(sub => `
${sub.title} ✕
`).join(''); ``` ### Technical Analysis Task data fetched from GitHub is interpolated into HTML strings and assigned to `innerHTML`. The affected values include task titles, descriptions, tags, IDs, prio ...[truncated 2028 chars]
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Error
Location
assets/index.html:3512
Finding

Long-Lived GitHub and Gateway Bearer Tokens Are Stored in Browser Local Storage

Content
View full analysis
Remediation
View remediation

T03 · Remote Payload Retrieval and Execution

Warning
Location
docs/PREREQUISITES.md:18
Finding

Installation Instructions Execute a Mutable Remote Script Directly in a Shell

Content
View full analysis
Remediation
View remediation

T05 · Unauthorized Access and Privilege Escalation

Error
Location
scripts/cors-proxy.js:5
Finding

Unrestricted CORS Proxy Exposes the Local Agent Gateway on Every Network Interface

Content
View full analysis
{ Object.entries(CORS_HEADERS).forEach(([k, v]) => res.setHeader(k, v)); if (req.method === 'OPTIONS') { res.writeHead(204); res.end(); return; } const targetUrl = new URL(req.url, TARGET); const proxyReq = http.request(targetUrl, { method: req.method, headers: { ...req.headers, host: targetUrl.host } }, (proxyRes) => { const headers = { ...proxyRes.headers, ...CORS_HEADERS }; res.writeHead(proxyRes.statusCode, headers); proxyRes.pipe(res); }); proxyReq.on('error', (e) => { res.writeHead(502); res.end('Proxy error: ' + e.message); }); req.pipe(proxyReq); }); ``` ```js server.listen(PORT, '0.0.0.0', () => { console.log(`CORS proxy on :${PORT} → ${TARGET}`); }); ``` ### Technical Analysis The proxy binds to `0.0.0.0`, making it reachable through every active network interface rather than only from the local machine. It permits every browser origin, forwards all common mutating HTTP methods, accepts authorization headers, and proxies arbitrary request paths to the local gateway. The proxy does not enforce: - An origin allowlist. - Its own authentication. - A route or tool allowlist. - HTTP method restrictions. - Request-body limits. - Rate limiting. - Network-peer restrictions. Although the upstream gateway may require a bearer token, the proxy unnecessarily expands its network and browse ...[truncated 1377 chars]
Remediation
View remediation
Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Tool MisuseTool Parameter Abuse, Chaining Abuse, Unsafe Defaults
Findings (102)

Tool Parameter Abuse

High
Category
Tool Misuse
Confidence
80% confidence
Finding

Tool parameters are crafted to achieve unintended or unsafe behavior. Parameter abuse can bypass intended safety checks (e.g. shell=True, --force, dangerous glob patterns).

Content

Scanner excerpt · CHANGELOG.md (reported line 35)May include surrounding context.

md
- `POST /api/crons/:id/run` → `gatewayInvoke('cron', { action: 'run', jobId })`
- `PATCH /api/crons/:id` → `gatewayInvoke('cron', { action: 'update', jobId, patch })`
- `DELETE /api/crons/:id` → `gatewayInvoke('cron', { action: 'remove', jobId })`
- `POST /api/crons` → `gatewayInvoke('cron', { action: 'add', job })`

---

Tp4

High
Category
MCP Tool Poisoning
Confidence
99% confidence
Finding

The declared description is about task management via a Kanban dashboard or CLI, but the code shown has no task, board, dashboard, or work-item management functionality. Its sole purpose is networking infrastructure: accepting HTTP requests, replying to OPTIONS preflights, proxying traffic to another service, and setting wildcard CORS headers. That is a materially different primary purpose and introduces undeclared network/proxy capabilities unrelated to the stated triggers.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
99% confidence
Finding

The declared description says this skill is for Kanban-style task management via CLI or dashboard UI. However, the supplied code does not implement task tracking, Kanban columns, dashboard behavior, or CLI task management. Instead, it writes a static sanitized JSON file representing cron/scheduled task examples to an assets data path for open-source export. This is a materially different primary purpose and an unrelated capability, so the description does not accurately represent the code.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
97% confidence
Finding

The declared purpose is task and Kanban board management, but the supplied code chunk does not implement task management, CLI/dashboard interactions, or work-item tracking. Instead, it performs build-support functionality by reading git metadata and writing version information to a JSON file. This is a materially different primary purpose from the declared description, so it should be flagged as a mismatch.

Content

No source excerpt is available for this finding.

Hidden Instructions

High
Category
Prompt Injection
Confidence
70% confidence
Finding

Hidden instructions were detected in comments or invisible text. These could contain malicious directives. Manual review is recommended.

Content

Scanner excerpt · assets/index.html (reported line 2098)May include surrounding context.

html
</style>
</head>
<body>
    <!-- Login Required Screen (shown when not authenticated) -->
    <div id="login-screen" class="login-screen">
        <div class="login-container">
            <div class="login-logo">🎯</div>

Credential Access

High
Category
Privilege Escalation
Confidence
98% confidence
Finding

The skill explicitly instructs users to generate and paste a GitHub Personal Access Token with broad repo permissions into the web UI. Collecting long-lived credentials directly in page context is dangerous because any script compromise, XSS, browser extension, or shared-device exposure can leak repository-wide access.

Content

Scanner excerpt · assets/index.html (reported line 2113)May include surrounding context.

html
<div class="login-step">
                        <span class="login-step-num">1</span>
                        <div>
                            <strong>Create a Personal Access Token</strong>
                            <a href="https://github.com/settings/tokens/new?scopes=repo&description=Mission%20Control%20Dashboard" target="_blank" class="login-link">
                                Create token on GitHub →
                            </a>

Context-Inappropriate Capability

High
Category
Not specified by scanner
Confidence
98% confidence
Finding

The login flow instructs users to create a classic Personal Access Token with full repo scope, which is substantially broader than necessary for a task board. Combined with local token storage and later use against multiple GitHub API endpoints, compromise of the page or browser context would expose write access to repository contents and metadata.

Content

No source excerpt is available for this finding.

Hidden Instructions

High
Category
Prompt Injection
Confidence
70% confidence
Finding

Hidden instructions were detected in comments or invisible text. These could contain malicious directives. Manual review is recommended.

Content

Scanner excerpt · assets/index.html (reported line 2170)May include surrounding context.

html
<div class="nav-tab" data-view="people" onclick="switchView('people')">People</div>
            </nav>
            
            <!-- Search -->
            <div class="search-container">
                <div class="search-input-wrapper">
                    <input type="text"

Credential Access

High
Category
Privilege Escalation
Confidence
97% confidence
Finding

The documentation normalizes the use of a PAT with repo permissions for ordinary use, encouraging users to over-delegate access. In context, this is especially risky because the same application also performs repository writes and collaborator enumeration.

Content

Scanner excerpt · assets/index.html (reported line 2388)May include surrounding context.

html
<h3 style="margin: 1.5rem 0 0.5rem;">Connect to GitHub</h3>
                <p style="color: var(--text-secondary); line-height: 1.6;">
                    Click <strong>"Connect GitHub"</strong> in the top right corner. You'll need a GitHub Personal Access Token with <code>repo</code> permissions.
                </p>
                <ol style="color: var(--text-secondary); line-height: 1.8; margin-left: 1.5rem;">
                    <li>Go to <a href="https://github.com/settings/tokens" target="_blank" style="color: var(--accent);">GitHub Settings → Tokens</a></li>

Hidden Instructions

High
Category
Prompt Injection
Confidence
70% confidence
Finding

Hidden instructions were detected in comments or invisible text. These could contain malicious directives. Manual review is recommended.

Content

Scanner excerpt · assets/index.html (reported line 2506)May include surrounding context.

html
</div>
    </div><!-- END view-docs -->

    <!-- PEOPLE VIEW -->
    <div id="view-people" class="view" style="display: none;">
        <div class="people-container">
            <div class="people-header">

Credential Access

High
Category
Privilege Escalation
Confidence
98% confidence
Finding

The auth modal actively solicits a GitHub Personal Access Token and guides the user through creating one. This is direct credential harvesting behavior from a security perspective, even if intended for convenience, because the page receives a reusable bearer secret with broad privileges.

Content

Scanner excerpt · assets/index.html (reported line 2540)May include surrounding context.

html
<div class="step">
                        <span class="step-number">1</span>
                        <div class="step-content">
                            <div class="step-title">Create a Personal Access Token</div>
                            <div class="step-description">
                                <a href="https://github.com/settings/tokens/new?scopes=repo&description=Mission%20Control%20Dashboard" target="_blank">
                                    Click here to create a token →

Credential Access

High
Category
Privilege Escalation
Confidence
99% confidence
Finding

The page includes a password input for GitHub PAT entry and later stores the token in localStorage, exposing a long-lived credential to any script running in the origin. This creates a high-value credential theft risk with potential full repository compromise.

Content

Scanner excerpt · assets/index.html (reported line 2565)May include surrounding context.

html
</div>

                <div class="form-group">
                    <label class="form-label">GitHub Personal Access Token</label>
                    <input type="password" class="form-input" id="token-input" placeholder="ghp_xxxxxxxxxxxxxxxxxxxx" autocomplete="off">
                    <div class="form-hint">
                        🔒 Your token is stored locally and never sent anywhere except GitHub.

Hidden Instructions

High
Category
Prompt Injection
Confidence
70% confidence
Finding

Hidden instructions were detected in comments or invisible text. These could contain malicious directives. Manual review is recommended.

Content

Scanner excerpt · assets/index.html (reported line 2659)May include surrounding context.

html
</div>
    </div>

    <!-- Commit Modal -->
    <div class="modal-overlay" id="commit-modal" onclick="if(event.target===this)hideCommitModal()">
        <div class="modal">
            <div class="modal-header">

Hidden Instructions

High
Category
Prompt Injection
Confidence
70% confidence
Finding

Hidden instructions were detected in comments or invisible text. These could contain malicious directives. Manual review is recommended.

Content

Scanner excerpt · assets/index.html (reported line 2688)May include surrounding context.

html
</div>
    </div>

    <!-- Task Edit Modal -->
    <div class="modal-overlay" id="task-modal" onclick="if(event.target===this)hideTaskModal()">
        <div class="modal" style="max-width: 600px;">
            <div class="modal-header">

Hidden Instructions

High
Category
Prompt Injection
Confidence
70% confidence
Finding

Hidden instructions were detected in comments or invisible text. These could contain malicious directives. Manual review is recommended.

Content

Scanner excerpt · assets/index.html (reported line 2741)May include surrounding context.

html
<input type="hidden" id="task-tags">
                </div>

                <!-- Subtasks Section -->
                <div class="form-group" id="subtasks-section">
                    <label class="form-label">Subtasks</label>
                    <div class="subtasks-list" id="subtasks-list"></div>

Description-Behavior Mismatch

High
Category
Not specified by scanner
Confidence
97% confidence
Finding

The skill materially exceeds a kanban/task-dashboard scope by adding cron execution, editing, and gateway control capabilities. That broadens the trust boundary from repository-backed task management into live operational automation, enabling users or agents to trigger recurring jobs or modify automation through an external service.

Content

No source excerpt is available for this finding.

Hidden Instructions

High
Category
Prompt Injection
Confidence
70% confidence
Finding

Hidden instructions were detected in comments or invisible text. These could contain malicious directives. Manual review is recommended.

Content

Scanner excerpt · assets/index.html (reported line 7100)May include surrounding context.

html
});
    </script>

    </div><!-- End Dashboard -->

    <script>
        // === LOGIN/AUTH GATE ===

Context-Inappropriate Capability

High
Category
Not specified by scanner
Confidence
96% confidence
Finding

This file performs direct outbound network operations to GitHub and Slack, pulling repository data and sending notifications outside the local task-board boundary. In the context of a skill presented as dashboard/CLI functionality, these transmissions materially increase risk because repository content, comments, and metadata can be exfiltrated or propagated to third-party systems.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

High
Category
Not specified by scanner
Confidence
97% confidence
Finding

The transform does much more than a passive dashboard helper: it automatically posts to Slack and wakes an external agent based on repository changes. That creates an autonomous execution path where repository-authored task content can trigger actions and downstream processing without an explicit user approval step, which is a meaningful expansion of capability beyond the declared skill scope.

Content

No source excerpt is available for this finding.

Credential Access

High
Category
Privilege Escalation
Confidence
96% confidence
Finding

The documented use of a GitHub Personal Access Token in browser localStorage creates a credible credential-access opportunity because any successful script injection, malicious browser extension, or local user compromise could read and exfiltrate the token. In a system that commits to a repository and drives downstream automation, theft of that token could enable tampering with tasks, triggering workflows, or broader source-control abuse.

Content

Scanner excerpt · docs/HOW-IT-WORKS.md (reported line 59)May include surrounding context.

md
- Displays Kanban board with drag-and-drop
- Commits changes back to the repository

**Authentication:** Uses GitHub Personal Access Token stored in browser localStorage.

**Deployment:** Automatic via GitHub Actions on every push.

External Script Fetching

High
Category
Supply Chain
Confidence
98% confidence
Finding

Using 'curl ... | sh' executes a remotely fetched script immediately without inspection or integrity verification. In setup documentation, this is dangerous because a compromised upstream server, mirror, or network path could lead to arbitrary code execution on the user's machine.

Content

Scanner excerpt · docs/PREREQUISITES.md (reported line 18)May include surrounding context.

Linux:

bash
curl -fsSL https://tailscale.com/install.sh | sh

Windows:

Chaining Abuse

High
Category
Tool Misuse
Confidence
99% confidence
Finding

Piping a downloaded script directly to 'sh' is a classic unsafe chaining pattern that enables immediate execution of unverified remote code. In the context of agent skill setup docs, this is especially risky because users may follow instructions automatically and grant broad execution without scrutiny.

Content

Scanner excerpt · docs/PREREQUISITES.md (reported line 18)May include surrounding context.

Linux:

bash
curl -fsSL https://tailscale.com/install.sh | sh

Windows:

Credential Access

High
Category
Privilege Escalation
Confidence
70% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · docs/PREREQUISITES.md (reported line 88)May include surrounding context.

sudo apt install gh

Or via official repo

curl -fsSL https://cli.github.com/packages/githubcli-archive-keyring.gpg | sudo dd of=/usr/share/keyrings/githubcli-archive-keyring.gpg echo "deb [arch=$(dpkg --print-architecture) signed-by=/usr/share/keyrings/githubcli-archive-keyring.gpg] https://cli.github.com/packages stable main" | sudo tee /etc/apt/sources.list.d/github-cli.list > /dev/null sudo apt update && sudo apt install gh

text

Credential Access

High
Category
Privilege Escalation
Confidence
70% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · docs/PREREQUISITES.md (reported line 89)May include surrounding context.

sudo apt install gh

Or via official repo

curl -fsSL https://cli.github.com/packages/githubcli-archive-keyring.gpg | sudo dd of=/usr/share/keyrings/githubcli-archive-keyring.gpg echo "deb [arch=$(dpkg --print-architecture) signed-by=/usr/share/keyrings/githubcli-archive-keyring.gpg] https://cli.github.com/packages stable main" | sudo tee /etc/apt/sources.list.d/github-cli.list > /dev/null sudo apt update && sudo apt install gh

text

Chaining Abuse

High
Category
Tool Misuse
Confidence
94% confidence
Finding

Piping remote content directly into a sudo command combines untrusted network input with privileged execution flow. This chaining pattern is risky because it removes opportunities for verification and can turn a supply-chain compromise into immediate system-level impact.

Content

Scanner excerpt · docs/PREREQUISITES.md (reported line 88)May include surrounding context.

sudo apt install gh

Or via official repo

curl -fsSL https://cli.github.com/packages/githubcli-archive-keyring.gpg | sudo dd of=/usr/share/keyrings/githubcli-archive-keyring.gpg echo "deb [arch=$(dpkg --print-architecture) signed-by=/usr/share/keyrings/githubcli-archive-keyring.gpg] https://cli.github.com/packages stable main" | sudo tee /etc/apt/sources.list.d/github-cli.list > /dev/null sudo apt update && sudo apt install gh

text

Static analysis

Detected: suspicious.env_credential_access, suspicious.exposed_secret_literal, suspicious.install_untrusted_source (+1 more)

Environment variable access combined with network send.

Critical
Code
suspicious.env_credential_access
Location
assets/transforms/github-mission-control.mjs:26

File appears to expose a hardcoded API secret or token.

Critical
Code
suspicious.exposed_secret_literal
Location
assets/data/tasks.json:12

Install source points to URL shortener or raw IP.

Warn
Code
suspicious.install_untrusted_source
Location
assets/examples/mission-control.json:3

Sensitive-looking file read is paired with a network send.

Warn
Code
suspicious.potential_exfiltration
Location
assets/transforms/github-mission-control.mjs:166