Back to skill

Security audit

fizzy.do - have your agent read, understand and update your fizzy.do boards

Security checks for vulnerabilities and agentic risk

Overview

The skill is a Fizzy CLI command guide whose authentication and board-management actions match its stated purpose, though users should handle tokens and live data changes carefully.

Install this only if you trust the Fizzy CLI and the account scope you will use. Prefer short-lived or scoped tokens, avoid exposing tokens or login codes in shared terminals, logs, or command history, protect the local Fizzy config file, and verify board or card IDs before running destructive or mutating commands.

Vulnerability Patterns
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (1)

T09 · Insecure Skill Coding Practices

Warning
Location
SKILL.md:15
Finding

Authentication Secrets Exposed Through Command-Line Arguments

Content
View full analysis

Vulnerability Details

File Location: SKILL.md, lines 15–20
Vulnerability Type: Authentication credential exposure through process arguments
Risk Level: Medium

Vulnerable Code:

sh
1) Authenticate
- Token:
  - `fizzy-cli auth login --token $FIZZY_TOKEN`
- Magic link:
  - `fizzy-cli auth login --email user@example.com`
  - If non-interactive, pass `--code ABC123`.

Technical Analysis

The documented commands pass an API token or one-time authentication code as command-line arguments. The shell expands $FIZZY_TOKEN before launching fizzy-cli, placing the resulting secret in the process argument vector. Depending on operating-system permissions and monitoring configuration, command arguments may be visible through process-inspection utilities, audit systems, telemetry agents, debugging tools, or command-execution wrappers.

The magic-link code supplied through --code is exposed through the same mechanism. Although such a code may be short-lived, disclosure before expiration can permit unauthorized authentication.

Attack Path

  1. A legitimate user follows the documented authentication procedure and invokes fizzy-cli with a token or magic-link code.
  2. The shell expands the environment variable or literal code into the child process's argument vector.
  3. A local user, monitoring agent, process collector, audit service, or execution wrapper with sufficient visibility records or inspects those arguments.
  4. The observer extracts the token or still-valid one-time code.
  5. The exposed credential is replayed against Fizzy to authenticate as the affected user.
  6. The attacker can perform operations permitted by that credential until it expires or is revoked.

Impact Assessment

Successful exploitation may provide access to the affected Fizzy account and its authorized resources. The resulting scope depends on the privileges associated with the exposed token or account and may in ...[truncated 282 chars]

Remediation
View remediation

Remediation Suggestions

  • Add a protected standard-input option such as fizzy-cli auth login --token-stdin, and document it as the preferred non-interactive authentication method.
  • For interactive authentication, read tokens and one-time codes using a hidden prompt that disables terminal echo.
  • If the current CLI cannot accept secrets securely, update it before recommending token-based automation.
  • Avoid supplying tokens, passwords, and one-time authentication codes as command-line arguments.
  • Ensure authentication secrets are redacted from application logs, shell tracing, audit output, telemetry, and error messages.
  • Store long-lived tokens in a dedicated secret manager or credential store with least-privilege permissions and rotate any credential suspected of exposure.
  • Use short-lived, narrowly scoped credentials where supported.
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Findings (3)

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

The skill documents destructive commands such as board deletion without any caution that they affect live production data or guidance to verify the target before execution. In an agent-skill context, this increases the chance of accidental destructive actions, especially if an automated agent follows examples literally.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
90% confidence
Finding

The card commands include multiple state-changing operations such as create, update, move, close, reopen, triage, and comment creation, but the skill does not warn that these modify real user data. In a workflow-automation setting, omission of that warning can lead to unintended changes to live boards and records.

Content

No source excerpt is available for this finding.

Missing User Warnings

Low
Category
Not specified by scanner
Confidence
86% confidence
Finding

The authentication and configuration section instructs users to pass tokens and persist configuration but does not warn about credential sensitivity, shell history exposure, or storage of secrets in config files. This can lead to inadvertent disclosure of access tokens or long-lived session material on shared systems.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.