Back to skill

Security audit

Monday Ops

Security checks for vulnerabilities and agentic risk

Overview

This skill is mostly a monday.com workspace helper, but it gives broad real-workspace mutation guidance and expands into Gmail, Google Calendar, and Fireflies without clear consent boundaries.

Install only if you want an agent to operate monday.com using your connected account. Before using it, explicitly name the target board or workspace, review any bulk changes or deletions, and require previews before transcript imports, raw GraphQL calls, calendar event creation, or Gmail draft generation.

Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
Findings (8)

Context-Inappropriate Capability

Medium
Confidence
91% confidence
Finding
The skill is scoped and branded as a monday.com operations skill, but it explicitly instructs the agent to branch into Google Calendar, Gmail, and Fireflies workflows. That scope expansion can cause unintended cross-service actions, data sharing, or connector use beyond what the user expected when invoking a monday.com-specific skill. In context, this is more dangerous because project-management data often contains sensitive internal task details that could be propagated into other systems without sufficiently explicit user intent.

Context-Inappropriate Capability

Medium
Confidence
95% confidence
Finding
The skill is described as monday.com-focused, but the documented workflows extend into Google Calendar, Fireflies, and Gmail actions. This broadens the effective data-sharing boundary and can cause users or downstream agents to move monday.com data into third-party systems without clear scoping, approval, or privacy review.

Vague Triggers

Medium
Confidence
86% confidence
Finding
The trigger text includes generic phrases such as "create a task," "update status," "project board," and "work tracker," which are common across many tools and could cause this skill to activate when the user did not intend to use monday.com. Misactivation matters here because the skill contains operational guidance for creating and modifying real workspace objects, so an accidental trigger could steer the agent toward the wrong connector or prompt for actions against the wrong system. The monday.com context reduces direct exploitability somewhat, but the broad automation scope makes unintended action selection materially risky.

Missing User Warnings

Medium
Confidence
93% confidence
Finding
The meeting workflow instructs the agent to extract action items from notes or transcripts and copy excerpts into monday.com updates, but it does not require warning the user that potentially sensitive meeting content will be persisted in a work-management system. This can expose confidential discussion, personal data, or privileged material to broader board audiences than intended.

Missing User Warnings

Low
Confidence
78% confidence
Finding
Cross-board reporting aggregates data from multiple boards, which may have different audiences, sensitivity levels, or access expectations. Without a user-facing warning or confirmation, the agent could combine and surface information in ways the user did not realize, increasing accidental overexposure of project data.

Missing User Warnings

Medium
Confidence
94% confidence
Finding
The Google Calendar workflow transfers monday.com item names and due-date data into an external calendar system without any stated warning or consent step. That can leak task metadata, schedules, and potentially sensitive project names into another platform with different sharing settings and retention policies.

Missing User Warnings

Medium
Confidence
93% confidence
Finding
The Fireflies integration imports transcript-derived content into monday.com without warning that meeting-derived text may be stored on project boards. This creates a risk of propagating sensitive statements, personal information, or confidential meeting context into a broader collaboration surface.

Missing User Warnings

Medium
Confidence
94% confidence
Finding
The Gmail workflow uses assignee email addresses and task details to generate email drafts but does not warn users that this information will be processed for outbound communication. This can expose internal task names, status information, or personal contact data through email channels that may be less controlled than monday.com.

Static analysis

No suspicious patterns detected.