Back to skill

Security audit

CS Coordinator agent

Security checks for vulnerabilities and agentic risk

Overview

This skill is a reasonable support-triage helper, but it may persist customer and payment/order identifiers in plain local case logs without enough privacy controls.

Review before installing if your support cases may include customer identifiers, payment or order references, billing details, or incident notes. Use an approved tracker when possible; if local logs are used, mask sensitive fields, keep logs out of source control and shared sync folders, restrict access, and define retention/deletion rules.

Vulnerability Patterns
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (1)

T09 · Insecure Skill Coding Practices

Warning
Location
SKILL.md:24
Finding

Plaintext Durable Storage of Customer and Payment Identifiers

Content
View full analysis

Vulnerability Details

File Location: SKILL.md, lines 24–37 and 141–161; references/log-only-workflow.md, lines 5–7 and 34–39
Vulnerability Type: Plaintext storage of potentially sensitive customer and transaction data
Risk Level: Medium

Vulnerable Code Snippets

From SKILL.md, lines 24–37:

md
## Issue Skeleton
- Customer Issue:
- Reported Symptom:
- Product/Plan:
- Time First Noticed:
- Scope:
- Payment/Order Reference:
- Customer Identifier:
- Current Impact:
- Known Signals:
- Missing Critical Info:

Rules:
- Fill from explicit facts when possible.

From SKILL.md, lines 141–161:

md
### Option B: log-only management
Use log-only management when no issue tracker is available or when a lightweight local workflow is preferred.

Recommended log pattern:
- store one case record per line in `cases.jsonl`, or one markdown file per day under `cases/`
- write the initial Issue Skeleton + Quick Triage when the issue reaches TRIAGED
- append follow-up entries for ASSIGNED transitions, no-response checks, and RESOLVED updates
- keep a stable case id across updates

Suggested JSONL fields:
- case_id
- created_at
- updated_at
- source
- category
- severity
- state
- title
- skeleton
- likely_module
- primary_owner
- backup_owner
- next_actions
- notes

From references/log-only-workflow.md, lines 5–7 and 34–39:

md
## Storage options
- `cases.jsonl` with one case event per line
- `cases/YYYY-MM-DD.md` daily markdown logs
- both, if you want machine-readable state plus human-readable summaries
md
## Recording pattern
1. Create a case record when the issue reaches TRIAGED.
2. Append new events for ASSIGNED, no-response follow-up, mitigation, and RESOLVED.
3. Keep a stable case id across all updates.
4. Never overwrite earlier reasoning without leaving a new event.
5. Keep the log factual and operational.

Technical Analysis

The mandatory issue skeleton collects a Payment/Order Reference and `Customer Identifie ...[truncated 1923 chars]

Remediation
View remediation

Remediation Suggestions

  1. Do not persist direct customer identifiers or full payment/order references by default.
  2. Replace sensitive values with opaque case IDs, tokenized identifiers, or masked references such as the final four characters.
  3. Require explicit user approval before storing sensitive case fields locally.
  4. Define a field-level allowlist for durable logs and exclude unnecessary free-form customer content.
  5. Store sensitive records only in an access-controlled tracker or encrypted datastore where available.
  6. If local logging is necessary, require owner-only file and directory permissions and verify them before writing.
  7. Add cases.jsonl and cases/ to source-control ignore rules and warn against committing or externally synchronizing these records.
  8. Establish documented retention periods, secure deletion procedures, and a process for removing records on request.
  9. Separate operational metadata from sensitive identifiers so lifecycle events can be retained without duplicating protected data.
  10. Add explicit guidance prohibiting authentication secrets, full payment-card data, security codes, passwords, session tokens, and similar credentials from ever being entered into the skeleton.
Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Findings (2)

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The skill explicitly instructs durable case tracking while its required issue skeleton includes fields such as customer identifiers and payment/order references. Without requiring data minimization, redaction, access controls, or a persistence warning, operators may store sensitive support data in trackers or logs indefinitely, increasing privacy and compliance risk.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

The log-only workflow recommends storing one case record per line in local JSONL files or daily markdown files, which can easily persist sensitive support information outside controlled ticketing systems. Because the surrounding workflow collects customer, payment, and incident details, this creates a realistic risk of unauthorized access, over-retention, and accidental disclosure.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.