Back to skill

Security audit

Hannah & Elena client skill for coworker integration by Sokosumi

Security checks for vulnerabilities and agentic risk

Overview

This skill is a disclosed connector to external Hannah and Elena AI services, so its network and credential use fit its stated purpose, though users should treat sent prompts and attachments as third-party data sharing.

Install only if you intend to share requests with Serviceplan/Sumike external services. Do not send secrets, regulated personal data, or confidential business files unless your organization has approved the service terms, data processing agreement, retention policy, and credential handling practices.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
Findings (15)

External Transmission

Medium
Category
Data Exfiltration
Confidence
60% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · API_GUIDE.md (reported line 69)May include surrounding context.

1. List Available Coworkers

bash
curl -X GET https://hannah.sumike.ai/v1/coworkers \
  -H "Authorization: Bearer sk-sumike-your-key-here"

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The guide instructs users to send prompts, prior assistant messages, and detailed business context to external services, but it does not warn that this transmits potentially sensitive data off-platform. In a skill whose purpose is to connect to remote AI coworkers, omission of data-sharing/privacy guidance can lead users to disclose confidential research, customer, or operational information unintentionally.

Content

No source excerpt is available for this finding.

External Transmission

Medium
Category
Data Exfiltration
Confidence
60% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · API_GUIDE.md (reported line 335)May include surrounding context.

Processing Streaming Response in JavaScript

javascript
const response = await fetch('https://hannah.sumike.ai/v1/chat/completions', {
  method: 'POST',
  headers: {
    'Authorization': 'Bearer sk-sumike-your-key-here',

External Transmission

Medium
Category
Data Exfiltration
Confidence
60% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · API_GUIDE.md (reported line 379)May include surrounding context.

401 Unauthorized

bash
curl -X POST https://hannah.sumike.ai/v1/chat/completions \
  -H "Authorization: Bearer invalid-key" \
  -H "Content-Type: application/json" \
  -d '{"messages":[{"role":"user","content":"test"}]}'

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

The debug section recommends verbose request inspection that reveals headers and full response bodies, but it does not warn that Authorization tokens and sensitive prompt/response content may be exposed in terminals, logs, shell history, or shared troubleshooting artifacts. This materially increases the chance of credential leakage and secondary disclosure of confidential data.

Content

No source excerpt is available for this finding.

External Transmission

Medium
Category
Data Exfiltration
Confidence
60% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · API_GUIDE.md (reported line 650)May include surrounding context.

md
max_attempts=5

while [ $attempt -le $max_attempts ]; do
  response=$(curl -s -w "%{http_code}" -X POST https://hannah.sumike.ai/v1/chat/completions \
    -H "Authorization: Bearer $HANNAH_KEY" \
    -H "Content-Type: application/json" \
    -d '{"messages":[{"role":"user","content":"test"}]}')

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The README encourages sending natural-language requests and receiving attachments through external email addresses without warning that prompts, business data, and attached files may contain sensitive or regulated information. In this skill’s context, users are likely to submit research briefs, planning documents, spreadsheets, and presentations to a third-party service, which creates confidentiality, compliance, and data-leakage risk if users assume the channel is safe by default.

Content

No source excerpt is available for this finding.

Intent-Code Divergence

Medium
Category
Not specified by scanner
Confidence
90% confidence
Finding

Earlier sections describe a task-based REST API using /v1/tasks and polling for results, while the later API reference describes direct OpenAI-style /v1/chat/completions endpoints as the primary API shape. These are materially different interaction models, so the documentation contradicts itself about what the code/interface actually does.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The API examples instruct the agent to send detailed task descriptions and business context to external services but do not clearly warn that this data leaves the local trust boundary. That omission increases the risk of inadvertent disclosure of sensitive strategy, customer information, or internal planning data to a third party.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The skill encourages sending natural-language requests and attachments over email to external third-party agents without an explicit warning about sensitive, regulated, or proprietary data disclosure. Users may forward confidential documents or personal data assuming this is an internal workflow, creating privacy, contractual, and compliance exposure.

Content

No source excerpt is available for this finding.

Missing User Warnings

Low
Category
Not specified by scanner
Confidence
84% confidence
Finding

The README tells users to export API keys directly into environment variables but does not state that these values are sensitive credentials that must be stored securely and never committed, logged, or shared. While environment variables are a common mechanism, omitting basic credential-handling guidance increases the chance of accidental exposure through shell history, screenshots, process dumps, CI logs, or misconfigured development environments.

Content

No source excerpt is available for this finding.

Intent-Code Divergence

Low
Category
Not specified by scanner
Confidence
81% confidence
Finding

The file states under 'AI Agents CAN' that agents can configure API keys in environment variables, but the surrounding guidance says humans must first obtain the keys and contact Serviceplan. This is an intent/documentation inconsistency about who performs credential setup, which could mislead users about the agent's role and authority.

Content

No source excerpt is available for this finding.

Intent-Code Divergence

Low
Category
Not specified by scanner
Confidence
93% confidence
Finding

The 'Available Tools' section documents tools such as hannah_create_task and elena_create_task, but later examples and the summary instruct agents to call hannah_research and elena_plan, which are not defined here. This is an active documentation contradiction that can misstate the skill's actual interface.

Content

No source excerpt is available for this finding.

Unpinned Dependencies

Low
Category
Supply Chain
Confidence
40% confidence
Finding

Dependencies lack version pinning, allowing potential malicious package updates. Consider pinning versions.

Content

Scanner excerpt · package.json (reported line 33)May include surrounding context.

json
},
  "dependencies": {},
  "devDependencies": {
    "typescript": "^5.3.0"
  },
  "peerDependencies": {},
  "files": [

Vague Triggers

Low
Category
Not specified by scanner
Confidence
87% confidence
Finding

This is a manifest file, so vague-trigger checks apply. The description says users can 'Connect to Hannah and Elena' and 'Access via OpenAI-compatible API or email' but does not define any specific trigger phrases, scope limits, or exclusion conditions, which could make activation expectations ambiguous.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.