T05 · Unauthorized Access and Privilege Escalation
- Location
prompts/diff-review.md:25- Finding
Unrestricted Collection of Agent Memory and Conversation History
- Content
View full analysis
- Remediation
View remediation
Security audit
Security checks for vulnerabilities and agentic risk
Vizboard is a useful dashboard generator, but it gives agents broad data access and file-changing instructions without enough user control.
Install only if you are comfortable with generated reports being saved under ~/.agent/diagrams and with workflows that may inspect repository history, local agent memory, and prior conversation context. Avoid using it on confidential projects unless you disable external CDN/font usage, external surf/gemini image generation, and in-place fact-check edits or require explicit approval before those actions.
prompts/diff-review.md:25Unrestricted Collection of Agent Memory and Conversation History
prompts/project-recap.md:32Project-Derived Information May Be Sent to an External AI Service
templates/mermaid-flowchart.html:343Generated Reports Execute Mutable JavaScript from External CDNs
templates/architecture.html:24Supposedly Self-Contained Reports Leak Viewer Metadata to Google Fonts
prompts/fact-check.md:38Fact-Check Workflow Can Overwrite Arbitrary Accessible Documents
The unconditional rm ./<file>.html step is a dangerous pattern because the filename is variable and the instruction normalizes destructive filesystem actions as part of routine execution. If the filename is ever influenced unexpectedly, resolved incorrectly, or collides with an existing workspace file, this could delete unintended user data; the forced 'always' behavior increases the risk.
**After generation, ALWAYS deliver the file to the user:**
1. Copy to workspace: `cp ~/.agent/diagrams/<file>.html ./<file>.html`
2. Send: `message(action="send", filePath="./<file>.html", message="<brief description of the dashboard>")`
3. Cleanup: `rm ./<file>.html`
4. Reply `NO_REPLY` after sending
**Do NOT skip step 2** — the user expects to receive the file in chat, not just a file path.
The prompt turns a visualization skill into a broad repository-analysis and fact-checking agent that reads arbitrary files, inspects git history, and derives conclusions from the wider codebase. That materially exceeds the declared scope of generating dashboards/visual pages, increasing the chance of unnecessary access to sensitive repository content and enabling capability creep under an unrelated skill label.
The prompt instructs the agent to edit the original target file in place, including rewriting sections when deemed 'fundamentally wrong,' despite the skill being positioned as a generator of visual pages. Direct modification of arbitrary user documents creates integrity risk, can overwrite important content, and enables destructive or unexpected changes outside the skill’s stated purpose.
Hidden instructions were detected in comments or invisible text. These could contain malicious directives. Manual review is recommended.
<svg class="connectors" style="position:absolute;inset:0;width:100%;height:100%;pointer-events:none;">
<path d="M 150,100 C 150,200 350,100 350,200" fill="none" stroke="var(--accent)" stroke-width="1.5" stroke-dasharray="4 3"/>
<!-- Arrowhead -->
<polygon points="348,195 352,205 356,195" fill="var(--accent)"/>
</svg>
Hidden instructions were detected in comments or invisible text. These could contain malicious directives. Manual review is recommended.
<meta charset="UTF-8">
<meta name="viewport" content="width=device-width, initial-scale=1.0">
<title>Architecture Diagram — Reference Template</title>
<!--
Reference template for the visual-explainer skill: CSS Grid architecture layout.
Warm terracotta/sage palette — distinctly different from the teal (mermaid)
and rose (data-table) templates so agents absorb variety, not a single palette.
Hidden instructions were detected in comments or invisible text. These could contain malicious directives. Manual review is recommended.
<meta charset="UTF-8">
<meta name="viewport" content="width=device-width, initial-scale=1.0">
<title>CI/CD Pipeline — Reference Template</title>
<!--
Reference template for the visual-explainer skill: Mermaid diagrams.
Teal/cyan palette — distinctly different from terracotta (architecture)
and rose (data-table) templates so agents absorb variety.
The description says to use the skill for 'any visual explanation of technical concepts' and also 'proactively' when rendering complex tables. This is an expansive activation scope without clear exclusion conditions or negative examples, which could cause unintended invocation for common technical-help requests.
The skill mandates creating, copying, sending, and deleting files automatically without user confirmation or visibility into the filesystem side effects. This can cause unintended file operations, overwrite collisions in the workspace, or accidental handling of sensitive generated content in ways the user did not explicitly approve.
The prompt explicitly directs the agent to mine conversation history and local memory/progress files outside the repository diff scope. That broadens data access from code review into potentially sensitive user data, prior session content, or unrelated project notes, creating an unnecessary confidentiality risk and possible cross-context data leakage.
The prompt instructs access to conversation history and local progress files without any privacy warning or consent step. Because these sources can contain unrelated secrets, internal discussions, or personal notes, silently including them in a diff-review workflow materially increases the risk of overcollection and disclosure.
Mining conversation history and agent memory files for design rationale can pull in sensitive information that is unrelated to the code diff, then surface it in the generated review. In this skill context, the instruction is especially risky because the output is a polished shareable artifact, which increases the chance that private data is unintentionally propagated or stored.
The optional use of an external image-generation CLI is not required for core diff rendering and may transmit code-derived context or prompts to another tool or service. Invoking auxiliary tooling increases attack surface, introduces possible data exfiltration paths, and can create nondeterministic side effects unrelated to the requested review.
Persisting generated reviews under ~/.agent/diagrams creates session-to-session residue that may contain sensitive repository structure, code-review observations, or inferred design rationale. Even if intended as convenience, retaining these artifacts in a shared or long-lived location increases exposure through later access, syncing, backup, or accidental disclosure.
**Optional illustrations** — if `surf` CLI is available (`which surf`), consider generating a hero banner or conceptual illustration via `surf gemini --generate-image` when it would enhance the page. Embed as base64 data URI. See css-patterns.md "Generated Images" for container styles. Skip if surf isn't available or the diff is purely structural.
Include responsive section navigation. Use diff-style visual language throughout: red for removed/before, green for added/after, yellow for modified, blue for neutral context. Write to `~/.agent/diagrams/` and open in browser.
Ultrathink.
The skill instructs writing output into a persistent directory and opening it in a browser without confirmation. This creates side effects beyond analysis, may expose sensitive diff content in local files or browser history, and violates the principle of requiring user consent before modifying the environment or launching applications.
The git-inspection instructions authorize commands such as git log, git diff, and git show even though the skill is described as a visualization tool. While not inherently malicious, this unjustified expansion of capability allows the skill to access historical code and metadata that may contain sensitive information unrelated to the user’s visualization request.
The prompt authorizes direct, surgical edits to the original file and even auto-selects a recent HTML file when no argument is supplied, without any confirmation step. This is dangerous because users may trigger silent modification of unintended documents, leading to loss of trust, accidental corruption, or tampering with artifacts they expected to remain read-only.
The prompt expands the skill from local HTML generation into optional invocation of an external AI image-generation CLI. That introduces an unnecessary capability boundary crossing for a diagram/dashboard skill and can cause user content or prompts to be sent to another tool/service without explicit approval, increasing data exposure and supply-chain risk.
The optional use of surf gemini --generate-image implies sending content to a potentially networked external service, but the prompt provides no disclosure or consent mechanism. If the rendered topic contains proprietary architecture, code context, or sensitive business data, that information could be exposed off-host.
Writing generated artifacts to ~/.agent/diagrams/ creates persistent local storage that may retain sensitive diagrams, plans, or architecture summaries beyond the current session. While persistence is part of the feature, storing outputs in a predictable long-lived location increases the chance of unintended retention or later disclosure.
If `surf` CLI is available (`which surf`), consider generating an AI illustration via `surf gemini --generate-image` when an image would genuinely enhance the page — a hero banner, conceptual illustration, or educational diagram that Mermaid can't express. Match the image style to the page's palette. Embed as base64 data URI. See css-patterns.md "Generated Images" for container styles. Skip images when the topic is purely structural or data-driven.
Write to `~/.agent/diagrams/` and open the result in the browser.
The prompt instructs the agent to write files under the user's home directory and open them in a browser without warning or obtaining consent. This creates side effects outside the chat boundary, can overwrite or accumulate artifacts, and can launch external applications unexpectedly.
The skill is described as a visualization/dashboard generator, but the prompt instructs it to perform broad codebase auditing, dependency tracing, verification of plan claims, and blast-radius analysis. This scope expansion increases access to potentially unrelated files and secrets and can cause over-collection of repository data beyond what is needed to render a visual review.
The prompt directs the skill to invoke an external image-generation CLI (surf gemini --generate-image) as part of producing output. That expands the skill from local HTML generation into tool execution and may send plan- or code-derived content to an external service, creating an unnecessary data-exfiltration and supply-chain surface for a visualization workflow.
The optional surf gemini --generate-image step may transmit repository- or plan-derived information to an external service, but the prompt provides no disclosure or consent requirement. In a plan-review context, generated prompts or conceptual diagrams may still encode sensitive architecture details, making silent third-party sharing risky.
Persisting generated plan reviews to ~/.agent/diagrams/ creates session-to-session residue that may contain sensitive architecture, roadmap, or code-derived analysis. Because the prompt standardizes a persistent location and does not mention cleanup, retention limits, or user consent, it increases the risk of unintended later access by users, tools, or processes on the same system.
**Optional illustrations** — if `surf` CLI is available (`which surf`), consider generating a conceptual illustration of the planned system via `surf gemini --generate-image` when it would help the reader visualize the change. Embed as base64 data URI. See css-patterns.md "Generated Images" for container styles. Skip if surf isn't available or the plan is purely structural.
Include responsive section navigation. Use a current-vs-planned visual language throughout: blue/neutral for current state, green/purple for planned additions, amber for areas of concern, red for gaps or risks. Write to `~/.agent/diagrams/` and open in browser.
Ultrathink.
The prompt instructs the agent to write files to ~/.agent/diagrams/ and open them in a browser without asking the user. That causes side effects outside the immediate response channel, may overwrite or persist sensitive derived content on disk, and may trigger browser-based execution or disclosure unexpectedly.
No suspicious patterns detected.