Back to skill

Security audit

Nerve Kanban

Security checks for vulnerabilities and agentic risk

Overview

This skill is a coherent local Kanban API helper, but it exposes irreversible deletion, autonomous task execution, and auto-approval settings without enough safety guidance.

Install only if you trust the local Nerve server and want the agent to manage that board. Require explicit human approval before permanent deletion, executing tasks, approving/completing work, or changing config; keep proposalPolicy set to confirm unless you intentionally want automatic task changes.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Tool MisuseTool Parameter Abuse, Chaining Abuse, Unsafe Defaults
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
Findings (20)

Tool Parameter Abuse

High
Category
Tool Misuse
Confidence
90% confidence
Finding

The skill exposes a permanent delete operation that can be invoked by an agent, enabling irreversible destruction of task records if used mistakenly, prompt-injected, or maliciously. In an autonomous tool-use context, destructive actions are more dangerous because agents may execute them based on ambiguous instructions or manipulated task content.

Content

Scanner excerpt · references/api.md (reported line 265)May include surrounding context.

md
---

### DELETE /api/kanban/tasks/:id

Permanently delete a task.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
89% confidence
Finding

The skill documentation prominently exposes destructive and state-changing operations such as delete, execute, approve, reject, abort, and config updates without any cautionary guidance, confirmation expectations, or operator-safety notes. In an agent setting, this increases the chance that a model or user will invoke impactful actions on the Kanban system without understanding that they mutate workflow state, trigger agent execution, or alter server configuration.

Content

No source excerpt is available for this finding.

External Transmission

Medium
Category
Data Exfiltration
Confidence
60% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · references/api.md (reported line 210)May include surrounding context.

Response: 201 with KanbanTask. ID is a URL-safe slug derived from title.

bash
curl -X POST http://localhost:3000/api/kanban/tasks \
  -H 'Content-Type: application/json' \
  -d '{
    "title": "Fix login bug",

External Transmission

Medium
Category
Data Exfiltration
Confidence
60% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · references/api.md (reported line 254)May include surrounding context.

Errors: 409 version_conflict if version mismatches (response includes serverVersion and latest task).

bash
curl -X PATCH http://localhost:3000/api/kanban/tasks/fix-login-bug \
  -H 'Content-Type: application/json' \
  -d '{
    "version": 1,

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
90% confidence
Finding

This markdown file documents a permanent deletion operation and provides a ready-to-run example, but it does not include any warning about data loss, recovery limitations, or the need for user confirmation before use. Under the markdown-specific missing-warning rule, destructive behavior affecting user data should be accompanied by an explicit warning.

Content

No source excerpt is available for this finding.

External Transmission

Medium
Category
Data Exfiltration
Confidence
60% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · references/api.md (reported line 300)May include surrounding context.

Errors: 409 version_conflict on stale version.

bash
curl -X POST http://localhost:3000/api/kanban/tasks/fix-login-bug/reorder \
  -H 'Content-Type: application/json' \
  -d '{ "version": 2, "targetStatus": "in-progress", "targetIndex": 0 }'

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
78% confidence
Finding

The endpoint documentation states that calling /execute spawns a gateway subagent session and triggers a background poller that can automatically transition task state. The description explains behavior, but it does not clearly warn users that invoking the endpoint starts autonomous processing with ongoing side effects beyond a simple state change.

Content

No source excerpt is available for this finding.

External Transmission

Medium
Category
Data Exfiltration
Confidence
60% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · references/api.md (reported line 327)May include surrounding context.

Side effects: Spawns a gateway subagent session with label kb-<id>. Background poller watches for completion and auto-transitions to review.

bash
curl -X POST http://localhost:3000/api/kanban/tasks/fix-login-bug/execute \
  -H 'Content-Type: application/json' \
  -d '{ "model": "claude-sonnet-4-20250514" }'

External Transmission

Medium
Category
Data Exfiltration
Confidence
60% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · references/api.md (reported line 351)May include surrounding context.

Errors: 409 invalid_transition if not in review.

bash
curl -X POST http://localhost:3000/api/kanban/tasks/fix-login-bug/approve \
  -H 'Content-Type: application/json' \
  -d '{ "note": "Looks good, merging." }'

External Transmission

Medium
Category
Data Exfiltration
Confidence
60% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · references/api.md (reported line 375)May include surrounding context.

Errors: 409 invalid_transition if not in review.

bash
curl -X POST http://localhost:3000/api/kanban/tasks/fix-login-bug/reject \
  -H 'Content-Type: application/json' \
  -d '{ "note": "Missed edge case with unicode chars. Retry." }'

External Transmission

Medium
Category
Data Exfiltration
Confidence
60% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · references/api.md (reported line 399)May include surrounding context.

Errors: 409 invalid_transition if not in in-progress with an active run.

bash
curl -X POST http://localhost:3000/api/kanban/tasks/fix-login-bug/abort \
  -H 'Content-Type: application/json' \
  -d '{ "note": "Taking too long, will rethink approach." }'

External Transmission

Medium
Category
Data Exfiltration
Confidence
60% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · references/api.md (reported line 427)May include surrounding context.

bash
# Success
curl -X POST http://localhost:3000/api/kanban/tasks/fix-login-bug/complete \
  -H 'Content-Type: application/json' \
  -d '{ "result": "Fixed the bug. Escaped special chars in auth handler." }'

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
88% confidence
Finding

The API exposes a configuration switch that enables automatic approval and application of proposals, removing human review from task creation and updates. In an agent-integrated kanban system, this materially increases the risk of unintended or malicious state changes, especially when proposals can be generated from agent output or external callers.

Content

No source excerpt is available for this finding.

Autonomous Decision Making

Medium
Category
Excessive Agency
Confidence
92% confidence
Finding

The proposalPolicy: 'auto' option enables autonomous approval and execution of proposed task changes without manual confirmation. In this skill's context, proposals may come from agents or be extracted from agent-produced results, so auto-approval can create a feedback loop where generated content directly mutates board state.

Content

Scanner excerpt · references/api.md (reported line 464)May include surrounding context.

md
| `reviewRequired` | boolean | |
| `allowDoneDragBypass` | boolean | |
| `quickViewLimit` | number (1-50) | |
| `proposalPolicy` | `'confirm'` \| `'auto'` | `auto` = proposals auto-approve |
| `defaultModel` | string (max 100) | Default model for task execution |
| `defaultThinking` | ThinkingLevel | Default thinking level |

External Transmission

Medium
Category
Data Exfiltration
Confidence
60% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · references/api.md (reported line 476)May include surrounding context.

Response: 200 with full updated KanbanBoardConfig.

bash
curl -X PUT http://localhost:3000/api/kanban/config \
  -H 'Content-Type: application/json' \
  -d '{
    "proposalPolicy": "auto",

External Transmission

Medium
Category
Data Exfiltration
Confidence
60% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · references/api.md (reported line 553)May include surrounding context.

bash
# Agent proposes a new task
curl -X POST http://localhost:3000/api/kanban/proposals \
  -H 'Content-Type: application/json' \
  -d '{
    "type": "create",

External Transmission

Medium
Category
Data Exfiltration
Confidence
60% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · references/api.md (reported line 610)May include surrounding context.

  • 409 already_resolved if already resolved.
bash
curl -X POST http://localhost:3000/api/kanban/proposals/abc-uuid/reject \
  -H 'Content-Type: application/json' \
  -d '{ "reason": "Not needed right now." }'

Internal Network Request

Medium
Category
Server-Side Request Forgery
Confidence
70% confidence
Finding

Code issues a request to a loopback, link-local, or private-range host. This can reach internal services not meant to be exposed and is a common SSRF pivot.

Content

Scanner excerpt · references/api.md (reported line 643)May include surrounding context.

javascript
// List todo tasks
const res = await fetch('http://localhost:3000/api/kanban/tasks?status=todo');
const { items, total, hasMore } = await res.json();

// Create a task

Internal Network Request

Medium
Category
Server-Side Request Forgery
Confidence
70% confidence
Finding

Code issues a request to a loopback, link-local, or private-range host. This can reach internal services not meant to be exposed and is a common SSRF pivot.

Content

Scanner excerpt · references/api.md (reported line 647)May include surrounding context.

javascript
// List todo tasks
const res = await fetch('http://localhost:3000/api/kanban/tasks?status=todo');
const { items, total, hasMore } = await res.json();

// Create a task

External Transmission

Medium
Category
Data Exfiltration
Confidence
60% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · references/api.md (reported line 647)May include surrounding context.

md
const { items, total, hasMore } = await res.json();

// Create a task
const task = await fetch('http://localhost:3000/api/kanban/tasks', {
  method: 'POST',
  headers: { 'Content-Type': 'application/json' },
  body: JSON.stringify({

Static analysis

No suspicious patterns detected.