Back to skill

Security audit

DocsBot

Security checks for vulnerabilities and agentic risk

Overview

This DocsBot administration skill can manage DocsBot bots and account resources through OAuth, but the inspected artifacts disclose that purpose and include scoped workflow, confirmation, and secret-handling guardrails.

Install this only if you want an agent to administer your DocsBot account through OAuth. Use a least-privileged DocsBot account where possible, review approval prompts carefully, expect the agent to read account/bot data and logs when relevant, and explicitly confirm destructive or high-impact changes such as deletions, member changes, webhooks, Skills, external MCP connectors, or public auto-reply behavior. Do not paste OAuth tokens or long-lived secrets into chat.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Memory PoisoningPersistent Context Injection, Context Window Stuffing, Memory Manipulation
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
Findings (15)

Anti-Refusal Statement

High
Category
Anti-Refusal
Confidence
80% confidence
Finding

Skill instructs the agent to omit warnings, disclaimers, or ethical commentary. Stripping safety caveats hides risk from the user and is a common jailbreak preamble.

Content

Scanner excerpt · references/bot-builder/SKILL.md (reported line 62)May include surrounding context.

md
- Public lead/support widgets skip safety/action decisions such as default `piiRedaction: false` unless requested, lead capture or explicit no-lead rationale, support/escalation URLs, and clearly justified action choices. Do not infer that a public widget should enable copy responses or link privacy.

Memory Manipulation

High
Category
Memory Poisoning
Confidence
80% confidence
Finding

Skill manipulates agent memory, state, or stored context. Memory corruption can alter personality, override safety rules, or cause unpredictable behavior.

Content

Scanner excerpt · references/bot-builder/assets/prompts/voice-sales.md (reported line 37)May include surrounding context.

md
2. Otherwise, use `search_documentation` for company, product, policy, process, pricing, or account/support questions when documentation lookup is needed.
3. If `human_escalation` is available and required by its instructions, escalate.
4. If no available tool fits, ask a brief clarifying question or say you do not have the capability to complete that request.
- Never invent pricing, discounts, availability, or commitments. Recommend products or next steps only when grounded in tool results or clear conversation facts.
- Escalate to a human if the caller asks, or if the `human_escalation` tool is available and the situation requires it (e.g., complex pricing negotiations).

## Guardrails

Memory Manipulation

High
Category
Memory Poisoning
Confidence
80% confidence
Finding

Skill manipulates agent memory, state, or stored context. Memory corruption can alter personality, override safety rules, or cause unpredictable behavior.

Content

Scanner excerpt · references/bot-builder/SKILL.md (reported line 50)May include surrounding context.

md
The logical `voicePrompt` channel is persisted as `voiceAgent.instructions` through `create_bot` or `update_bot`. It is not a top-level `voicePrompt` property. `draft_bot_prompt` supports agent/default tabs and cannot draft voice; do not call it with a voice tab.

For a new bot, save prepared instructions with `voiceAgent.enabled: false` unless the user has requested voice or clear context authorizes a phone agent/voice assistant. Ordinary website support, chat, branding or sales-bot setup alone does not authorize Advanced voice. An explicit voice request already authorizes activation within that scope; do not ask for duplicate confirmation. For an existing bot, preserve its current enabled state unless the user requests a change. A prompt save and an activation change are separate decisions, even if an authorized payload includes both.

## Safe Voice Object Writes

Memory Manipulation

High
Category
Memory Poisoning
Confidence
80% confidence
Finding

Skill manipulates agent memory, state, or stored context. Memory corruption can alter personality, override safety rules, or cause unpredictable behavior.

Content

Scanner excerpt · references/bot-builder/references/deployment/voice.md (reported line 17)May include surrounding context.

md
The logical `voicePrompt` channel is persisted as `voiceAgent.instructions` through `create_bot` or `update_bot`. It is not a top-level `voicePrompt` property. `draft_bot_prompt` supports agent/default tabs and cannot draft voice; do not call it with a voice tab.

For a new bot, save prepared instructions with `voiceAgent.enabled: false` unless the user has requested voice or clear context authorizes a phone agent/voice assistant. Ordinary website support, chat, branding or sales-bot setup alone does not authorize Advanced voice. An explicit voice request already authorizes activation within that scope; do not ask for duplicate confirmation. For an existing bot, preserve its current enabled state unless the user requests a change. A prompt save and an activation change are separate decisions, even if an authorized payload includes both.

## Safe Voice Object Writes

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

The trigger text is broad enough that an agent may invoke this administrative skill for loosely related DocsBot tasks without clear user intent. In an admin-capable skill, ambiguous activation increases the chance of over-privileged actions, unnecessary account inspection, or configuration changes being initiated in the wrong context.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
88% confidence
Finding

The skill instructs the agent to infer and set a primary language locale during bot creation rather than requiring explicit user approval. This can silently misconfigure customer-facing behavior, produce incorrect language handling for multilingual organizations, and create unwanted writes based on inference instead of consent.

Content

No source excerpt is available for this finding.

Autonomous Decision Making

Medium
Category
Excessive Agency
Confidence
80% confidence
Finding

Skill enables autonomous high-impact decisions without human-in-the-loop verification. Critical operations (destructive commands, financial transactions, data deletion) should require explicit user confirmation.

Content

Scanner excerpt · references/bot-builder/references/actions/billing.md (reported line 61)May include surrounding context.

md
- The JWT includes `team_id`, `bot_id`, `exp`, `iat`, and `metadata.priv_stripe_customer_id`.
- The widget or Chat Agent API sends the JWT as the bearer token.

Never ask the user to place `priv_stripe_customer_id` in client-side public metadata or `identify`. Private metadata must be signed by the backend.

## Refund And Cancellation Guardrails

Autonomous Decision Making

Medium
Category
Excessive Agency
Confidence
80% confidence
Finding

Skill enables autonomous high-impact decisions without human-in-the-loop verification. Critical operations (destructive commands, financial transactions, data deletion) should require explicit user confirmation.

Content

Scanner excerpt · references/bot-builder/references/actions/external-mcp.md (reported line 27)May include surrounding context.

md
- Do not run write-capable external MCP tools during setup unless the user explicitly authorizes that live action.
- Do not expose custom headers, OAuth tokens, or connector secrets.
- Do not ask the user to paste OAuth tokens or long-lived secrets into chat. Use the MCP connections dashboard page for authorization or credential entry whenever possible.
- Public bots should not use owner-scoped OAuth MCP tools for customer account actions unless the user explicitly accepts the scope model and risk.
- If a tool needs customer identity, add prompt rules to ask for it and refuse unsafe assumptions.
- Prefer non-user-scoped reads for public bots; reserve owner-scoped actions for internal/private bots.

Autonomous Decision Making

Medium
Category
Excessive Agency
Confidence
75% confidence
Finding

Skill enables autonomous high-impact decisions without human-in-the-loop verification. Critical operations (destructive commands, financial transactions, data deletion) should require explicit user confirmation.

Content

Scanner excerpt · references/bot-builder/references/evaluation/rubric.md (reported line 87)May include surrounding context.

md
- Critical defect: created in the wrong team, leaked secrets, deleted a review target before judging, failed to create the bot, or configured a dangerous action without scope warning.
- Major defect: new/full setup omits prepared voice instructions, stores a top-level `voicePrompt`, uses text-agent output as the voice preset, or resets unrelated writable voice settings.
- Major defect: enables Advanced voice, voice Skills or voice MCP selections without a user request or clear voice authorization; ordinary website/chat setup alone is insufficient.
- Major defect: no meaningful sources, no bot-specific `labels.firstMessage`/prompt, no verification, missing required handoff links, or source tags configured without any prompt/use rationale.
- Major defect: final handoff lacks a clear "try the bot now" link, customized next steps, or useful test prompts.
- Major defect: any failed or zero-content source in a critical tag is left unresolved while the handoff claims the bot is ready.
- Major defect: a broad final-product bot has only demo-scale source coverage without explicitly narrowing the prompt or labeling the setup as demo-scale.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The documentation includes a plugin installation command with an explicit --trust flag, which normalizes bypassing trust review for third-party plugin content. Although the surrounding text says to review the package before explicitly trusting it, the command still encourages a high-risk action in an admin-focused skill that can connect to a privileged remote MCP server, increasing the chance of users installing and authorizing unreviewed code or connectors.

Content

No source excerpt is available for this finding.

External Transmission

Medium
Category
Data Exfiltration
Confidence
50% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · references/bot-builder/references/deployment/helpscout-auto-drafting.md (reported line 18)May include surrounding context.

md
| Server | Endpoint | Tools | Best for |
| --- | --- | --- | --- |
| DocsBot | `https://mcp.docsbot.ai` | fixed named tools; `list_tool_categories`, `search_tools`, `get_tool_schema` for metadata | Administering DocsBot teams, bots, sources, members, account usage, integrations, Skills, and reporting through existing dashboard permissions. |
| Documentation MCP | `https://api.docsbot.ai/teams/{teamId}/bots/{botId}/mcp/` | `search`, `fetch` | Searching and retrieving one bot's indexed documentation/training sources. |
| Question History MCP | `https://api.docsbot.ai/teams/{teamId}/bots/{botId}/questions/mcp/` | `search`, `fetch` | Searching and retrieving prior support questions, answers, and conversation history for one bot. |

This package is for **DocsBot**.

External Transmission

Medium
Category
Data Exfiltration
Confidence
50% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · references/bot-builder/references/deployment/helpscout-auto-drafting.md (reported line 35)May include surrounding context.

md
| Server | Endpoint | Tools | Best for |
| --- | --- | --- | --- |
| DocsBot | `https://mcp.docsbot.ai` | fixed named tools; `list_tool_categories`, `search_tools`, `get_tool_schema` for metadata | Administering DocsBot teams, bots, sources, members, account usage, integrations, Skills, and reporting through existing dashboard permissions. |
| Documentation MCP | `https://api.docsbot.ai/teams/{teamId}/bots/{botId}/mcp/` | `search`, `fetch` | Searching and retrieving one bot's indexed documentation/training sources. |
| Question History MCP | `https://api.docsbot.ai/teams/{teamId}/bots/{botId}/questions/mcp/` | `search`, `fetch` | Searching and retrieving prior support questions, answers, and conversation history for one bot. |

This package is for **DocsBot**.

External Transmission

Medium
Category
Data Exfiltration
Confidence
50% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · references/mcp-server.md (reported line 8)May include surrounding context.

md
| Server | Endpoint | Tools | Best for |
| --- | --- | --- | --- |
| DocsBot | `https://mcp.docsbot.ai` | fixed named tools; `list_tool_categories`, `search_tools`, `get_tool_schema` for metadata | Administering DocsBot teams, bots, sources, members, account usage, integrations, Skills, and reporting through existing dashboard permissions. |
| Documentation MCP | `https://api.docsbot.ai/teams/{teamId}/bots/{botId}/mcp/` | `search`, `fetch` | Searching and retrieving one bot's indexed documentation/training sources. |
| Question History MCP | `https://api.docsbot.ai/teams/{teamId}/bots/{botId}/questions/mcp/` | `search`, `fetch` | Searching and retrieving prior support questions, answers, and conversation history for one bot. |

This package is for **DocsBot**.

External Transmission

Medium
Category
Data Exfiltration
Confidence
50% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · references/mcp-server.md (reported line 9)May include surrounding context.

md
| Server | Endpoint | Tools | Best for |
| --- | --- | --- | --- |
| DocsBot | `https://mcp.docsbot.ai` | fixed named tools; `list_tool_categories`, `search_tools`, `get_tool_schema` for metadata | Administering DocsBot teams, bots, sources, members, account usage, integrations, Skills, and reporting through existing dashboard permissions. |
| Documentation MCP | `https://api.docsbot.ai/teams/{teamId}/bots/{botId}/mcp/` | `search`, `fetch` | Searching and retrieving one bot's indexed documentation/training sources. |
| Question History MCP | `https://api.docsbot.ai/teams/{teamId}/bots/{botId}/questions/mcp/` | `search`, `fetch` | Searching and retrieving prior support questions, answers, and conversation history for one bot. |

This package is for **DocsBot**.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
81% confidence
Finding

The instruction 'Format all output in Markdown' imposes a fixed output format regardless of user preference. Under the policy scope for natural-language constraints, this is a format/locale-style restriction that is not presented as optional or justified by a documented regional or user-selected requirement.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.