Back to skill

Security audit

Vizboard

Security checks for vulnerabilities and agentic risk

Overview

Vizboard is a useful dashboard generator, but it gives agents broad data access and file-changing instructions without enough user control.

Install only if you are comfortable with generated reports being saved under ~/.agent/diagrams and with workflows that may inspect repository history, local agent memory, and prior conversation context. Avoid using it on confidential projects unless you disable external CDN/font usage, external surf/gemini image generation, and in-place fact-check edits or require explicit approval before those actions.

Vulnerability Patterns
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
Findings (5)

T05 · Unauthorized Access and Privilege Escalation

Error
Location
prompts/diff-review.md:25
Finding

Unrestricted Collection of Agent Memory and Conversation History

Content
View full analysis
Remediation
View remediation

T05 · Unauthorized Access and Privilege Escalation

Warning
Location
prompts/project-recap.md:32
Finding

Project-Derived Information May Be Sent to an External AI Service

Content
View full analysis
Remediation
View remediation

T03 · Remote Payload Retrieval and Execution

Error
Location
templates/mermaid-flowchart.html:343
Finding

Generated Reports Execute Mutable JavaScript from External CDNs

Content
View full analysis
``` ```html ``` ```html ``` ```html ``` ```html
Remediation
View remediation

T08 · Insecure Dependencies

Warning
Location
templates/architecture.html:24
Finding

Supposedly Self-Contained Reports Leak Viewer Metadata to Google Fonts

Content
View full analysis
``` ```html ``` ```html ``` ### Technical Analysis Opening any template-derived report initiates connections to Google Fonts infrastructure. The `preconnect` directives may establish external connections before the stylesheet is needed, while the stylesheet and font requests disclose network metadata. This behavior contradicts the explicit requirement in `SKILL.md:20` that generated HTML be fully self-contained and contain no external assets. It can also reveal that a report was opened, along with the viewer's IP address, connection timing, browser user-agent, and other request metadata available under browser policy. ### Attack Path 1. The Agent generates an HTML report from on ...[truncated 775 chars]
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Warning
Location
prompts/fact-check.md:38
Finding

Fact-Check Workflow Can Overwrite Arbitrary Accessible Documents

Content
View full analysis
Remediation
View remediation
Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Tool MisuseTool Parameter Abuse, Chaining Abuse, Unsafe Defaults
  • Rogue AgentSelf-Modification, Session Persistence
Findings (38)

Tool Parameter Abuse

High
Category
Tool Misuse
Confidence
95% confidence
Finding

The unconditional rm ./<file>.html step is a dangerous pattern because the filename is variable and the instruction normalizes destructive filesystem actions as part of routine execution. If the filename is ever influenced unexpectedly, resolved incorrectly, or collides with an existing workspace file, this could delete unintended user data; the forced 'always' behavior increases the risk.

Content

Scanner excerpt · SKILL.md (reported line 45)May include surrounding context.

md
**After generation, ALWAYS deliver the file to the user:**
1. Copy to workspace: `cp ~/.agent/diagrams/<file>.html ./<file>.html`
2. Send: `message(action="send", filePath="./<file>.html", message="<brief description of the dashboard>")`
3. Cleanup: `rm ./<file>.html`
4. Reply `NO_REPLY` after sending

**Do NOT skip step 2** — the user expects to receive the file in chat, not just a file path.

Description-Behavior Mismatch

High
Category
Not specified by scanner
Confidence
97% confidence
Finding

The prompt turns a visualization skill into a broad repository-analysis and fact-checking agent that reads arbitrary files, inspects git history, and derives conclusions from the wider codebase. That materially exceeds the declared scope of generating dashboards/visual pages, increasing the chance of unnecessary access to sensitive repository content and enabling capability creep under an unrelated skill label.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

High
Category
Not specified by scanner
Confidence
97% confidence
Finding

The prompt instructs the agent to edit the original target file in place, including rewriting sections when deemed 'fundamentally wrong,' despite the skill being positioned as a generator of visual pages. Direct modification of arbitrary user documents creates integrity risk, can overwrite important content, and enables destructive or unexpected changes outside the skill’s stated purpose.

Content

No source excerpt is available for this finding.

Hidden Instructions

High
Category
Prompt Injection
Confidence
70% confidence
Finding

Hidden instructions were detected in comments or invisible text. These could contain malicious directives. Manual review is recommended.

Content

Scanner excerpt · references/css-patterns.md (reported line 685)May include surrounding context.

html
<svg class="connectors" style="position:absolute;inset:0;width:100%;height:100%;pointer-events:none;">
  <path d="M 150,100 C 150,200 350,100 350,200" fill="none" stroke="var(--accent)" stroke-width="1.5" stroke-dasharray="4 3"/>
  <!-- Arrowhead -->
  <polygon points="348,195 352,205 356,195" fill="var(--accent)"/>
</svg>

Hidden Instructions

High
Category
Prompt Injection
Confidence
70% confidence
Finding

Hidden instructions were detected in comments or invisible text. These could contain malicious directives. Manual review is recommended.

Content

Scanner excerpt · templates/architecture.html (reported line 7)May include surrounding context.

html
<meta charset="UTF-8">
<meta name="viewport" content="width=device-width, initial-scale=1.0">
<title>Architecture Diagram — Reference Template</title>
<!--
  Reference template for the visual-explainer skill: CSS Grid architecture layout.
  Warm terracotta/sage palette — distinctly different from the teal (mermaid)
  and rose (data-table) templates so agents absorb variety, not a single palette.

Hidden Instructions

High
Category
Prompt Injection
Confidence
70% confidence
Finding

Hidden instructions were detected in comments or invisible text. These could contain malicious directives. Manual review is recommended.

Content

Scanner excerpt · templates/mermaid-flowchart.html (reported line 7)May include surrounding context.

html
<meta charset="UTF-8">
<meta name="viewport" content="width=device-width, initial-scale=1.0">
<title>CI/CD Pipeline — Reference Template</title>
<!--
  Reference template for the visual-explainer skill: Mermaid diagrams.
  Teal/cyan palette — distinctly different from terracotta (architecture)
  and rose (data-table) templates so agents absorb variety.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The description says to use the skill for 'any visual explanation of technical concepts' and also 'proactively' when rendering complex tables. This is an expansive activation scope without clear exclusion conditions or negative examples, which could cause unintended invocation for common technical-help requests.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The skill mandates creating, copying, sending, and deleting files automatically without user confirmation or visibility into the filesystem side effects. This can cause unintended file operations, overwrite collisions in the workspace, or accidental handling of sensitive generated content in ways the user did not explicitly approve.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

Medium
Category
Not specified by scanner
Confidence
97% confidence
Finding

The prompt explicitly directs the agent to mine conversation history and local memory/progress files outside the repository diff scope. That broadens data access from code review into potentially sensitive user data, prior session content, or unrelated project notes, creating an unnecessary confidentiality risk and possible cross-context data leakage.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

The prompt instructs access to conversation history and local progress files without any privacy warning or consent step. Because these sources can contain unrelated secrets, internal discussions, or personal notes, silently including them in a diff-review workflow materially increases the risk of overcollection and disclosure.

Content

No source excerpt is available for this finding.

Ssd 3

Medium
Category
Not specified by scanner
Confidence
98% confidence
Finding

Mining conversation history and agent memory files for design rationale can pull in sensitive information that is unrelated to the code diff, then surface it in the generated review. In this skill context, the instruction is especially risky because the output is a polished shareable artifact, which increases the chance that private data is unintentionally propagated or stored.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

Medium
Category
Not specified by scanner
Confidence
84% confidence
Finding

The optional use of an external image-generation CLI is not required for core diff rendering and may transmit code-derived context or prompts to another tool or service. Invoking auxiliary tooling increases attack surface, introduces possible data exfiltration paths, and can create nondeterministic side effects unrelated to the requested review.

Content

No source excerpt is available for this finding.

Session Persistence

Medium
Category
Rogue Agent
Confidence
90% confidence
Finding

Persisting generated reviews under ~/.agent/diagrams creates session-to-session residue that may contain sensitive repository structure, code-review observations, or inferred design rationale. Even if intended as convenience, retaining these artifacts in a shared or long-lived location increases exposure through later access, syncing, backup, or accidental disclosure.

Content

Scanner excerpt · prompts/diff-review.md (reported line 64)May include surrounding context.

md
**Optional illustrations** — if `surf` CLI is available (`which surf`), consider generating a hero banner or conceptual illustration via `surf gemini --generate-image` when it would enhance the page. Embed as base64 data URI. See css-patterns.md "Generated Images" for container styles. Skip if surf isn't available or the diff is purely structural.

Include responsive section navigation. Use diff-style visual language throughout: red for removed/before, green for added/after, yellow for modified, blue for neutral context. Write to `~/.agent/diagrams/` and open in browser.

Ultrathink.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The skill instructs writing output into a persistent directory and opening it in a browser without confirmation. This creates side effects beyond analysis, may expose sensitive diff content in local files or browser history, and violates the principle of requiring user consent before modifying the environment or launching applications.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The git-inspection instructions authorize commands such as git log, git diff, and git show even though the skill is described as a visualization tool. While not inherently malicious, this unjustified expansion of capability allows the skill to access historical code and metadata that may contain sensitive information unrelated to the user’s visualization request.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The prompt authorizes direct, surgical edits to the original file and even auto-selects a recent HTML file when no argument is supplied, without any confirmation step. This is dangerous because users may trigger silent modification of unintended documents, leading to loss of trust, accidental corruption, or tampering with artifacts they expected to remain read-only.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

The prompt expands the skill from local HTML generation into optional invocation of an external AI image-generation CLI. That introduces an unnecessary capability boundary crossing for a diagram/dashboard skill and can cause user content or prompts to be sent to another tool/service without explicit approval, increasing data exposure and supply-chain risk.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

The optional use of surf gemini --generate-image implies sending content to a potentially networked external service, but the prompt provides no disclosure or consent mechanism. If the rendered topic contains proprietary architecture, code context, or sensitive business data, that information could be exposed off-host.

Content

No source excerpt is available for this finding.

Session Persistence

Medium
Category
Rogue Agent
Confidence
84% confidence
Finding

Writing generated artifacts to ~/.agent/diagrams/ creates persistent local storage that may retain sensitive diagrams, plans, or architecture summaries beyond the current session. While persistence is part of the feature, storing outputs in a predictable long-lived location increases the chance of unintended retention or later disclosure.

Content

Scanner excerpt · prompts/generate-web-diagram.md (reported line 10)May include surrounding context.

md
If `surf` CLI is available (`which surf`), consider generating an AI illustration via `surf gemini --generate-image` when an image would genuinely enhance the page — a hero banner, conceptual illustration, or educational diagram that Mermaid can't express. Match the image style to the page's palette. Embed as base64 data URI. See css-patterns.md "Generated Images" for container styles. Skip images when the topic is purely structural or data-driven.

Write to `~/.agent/diagrams/` and open the result in the browser.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The prompt instructs the agent to write files under the user's home directory and open them in a browser without warning or obtaining consent. This creates side effects outside the chat boundary, can overwrite or accumulate artifacts, and can launch external applications unexpectedly.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

Medium
Category
Not specified by scanner
Confidence
84% confidence
Finding

The skill is described as a visualization/dashboard generator, but the prompt instructs it to perform broad codebase auditing, dependency tracing, verification of plan claims, and blast-radius analysis. This scope expansion increases access to potentially unrelated files and secrets and can cause over-collection of repository data beyond what is needed to render a visual review.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

Medium
Category
Not specified by scanner
Confidence
88% confidence
Finding

The prompt directs the skill to invoke an external image-generation CLI (surf gemini --generate-image) as part of producing output. That expands the skill from local HTML generation into tool execution and may send plan- or code-derived content to an external service, creating an unnecessary data-exfiltration and supply-chain surface for a visualization workflow.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
90% confidence
Finding

The optional surf gemini --generate-image step may transmit repository- or plan-derived information to an external service, but the prompt provides no disclosure or consent requirement. In a plan-review context, generated prompts or conceptual diagrams may still encode sensitive architecture details, making silent third-party sharing risky.

Content

No source excerpt is available for this finding.

Session Persistence

Medium
Category
Rogue Agent
Confidence
79% confidence
Finding

Persisting generated plan reviews to ~/.agent/diagrams/ creates session-to-session residue that may contain sensitive architecture, roadmap, or code-derived analysis. Because the prompt standardizes a persistent location and does not mention cleanup, retention limits, or user consent, it increases the risk of unintended later access by users, tools, or processes on the same system.

Content

Scanner excerpt · prompts/plan-review.md (reported line 82)May include surrounding context.

md
**Optional illustrations** — if `surf` CLI is available (`which surf`), consider generating a conceptual illustration of the planned system via `surf gemini --generate-image` when it would help the reader visualize the change. Embed as base64 data URI. See css-patterns.md "Generated Images" for container styles. Skip if surf isn't available or the plan is purely structural.

Include responsive section navigation. Use a current-vs-planned visual language throughout: blue/neutral for current state, green/purple for planned additions, amber for areas of concern, red for gaps or risks. Write to `~/.agent/diagrams/` and open in browser.

Ultrathink.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The prompt instructs the agent to write files to ~/.agent/diagrams/ and open them in a browser without asking the user. That causes side effects outside the immediate response channel, may overwrite or persist sensitive derived content on disk, and may trigger browser-based execution or disclosure unexpectedly.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.