Back to skill

Security audit

roundtable

Security checks for vulnerabilities and agentic risk

Overview

Roundtable is a coherent multi-agent helper, but it may save sensitive council questions to local logs even after a user chooses no logging.

Review this skill carefully before installing if you may ask it confidential, regulated, or proprietary questions. Its multi-agent behavior and web research are expected, but disable or fix logging before use: logging should be conditional on `log_sessions: true`, and sensitive sessions should not be persisted without explicit per-run consent.

Vulnerability Patterns
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (1)

T09 · Insecure Skill Coding Practices

Warning
Location
SKILL.md:421
Finding

Session Logging Proceeds Despite Explicit User Opt-Out

Content
View full analysis
Remediation
View remediation
Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Memory PoisoningPersistent Context Injection, Context Window Stuffing, Memory Manipulation
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
Findings (8)

Memory Manipulation

High
Category
Memory Poisoning
Confidence
80% confidence
Finding

Skill manipulates agent memory, state, or stored context. Memory corruption can alter personality, override safety rules, or cause unpredictable behavior.

Content

Scanner excerpt · README.md (reported line 294)May include surrounding context.

Respond ONLY with your structured analysis in the required format.

text

This mitigates prompt-injection attempts where user text tries to redefine roles or execution boundaries.

---

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The README states that full session logs are written to disk and explicitly includes the original question, but it does not prominently warn users that sensitive prompts, secrets, internal plans, or personal data may be persisted locally. In a multi-agent deliberation tool, users are likely to paste proprietary or regulated content, so silent persistence increases the chance of unintended data retention and later disclosure.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The skill can activate on broad natural-language phrases like 'ask the council' or 'multi-agent', which increases the chance of unintended invocation. In this skill, accidental activation is more consequential because it may spawn multiple sub-agents, incur extra cost, and trigger logging behavior, even though it does not directly grant dangerous system capabilities.

Content

No source excerpt is available for this finding.

Ssd 3

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The setup flow encourages persistent session logging to memory/roundtable/ and records user prompts and agent outputs in natural language. Because these contents can include sensitive business, personal, or security-related information, retaining them in plain form increases the risk of later disclosure through workspace access, backups, or other skills reading memory.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

The skill instructs the agent to save full session logs containing the original question and agent summaries, but it does not require a fresh user-facing notice or confirmation at execution time before each write. This creates a privacy risk because users may share sensitive content during a council run without realizing it will be retained in memory storage.

Content

No source excerpt is available for this finding.

Ssd 3

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

This section explicitly directs the agent to save the full council session log, including the original question, agent responses, and final synthesis, to memory storage. That creates a clear data retention surface for confidential prompts and derived analysis, and the risk is amplified because the skill is designed for complex, potentially sensitive deliberations.

Content

No source excerpt is available for this finding.

Intent-Code Divergence

Low
Category
Not specified by scanner
Confidence
98% confidence
Finding

The manifest declares version 0.5.0, but the required final output template hard-codes Roundtable v0.4.0-beta. This is an active contradiction in the skill's own documentation about what version it is presenting to users, not merely an omission.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
91% confidence
Finding

The config sets the language to "en" as a default, which is a natural-language locale constraint visible in a config value. Because there is no indication here that users can opt in to a different language or override the setting, this may violate the policy against forcing a specific language without user choice.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.