Back to skill

Security audit

Trello

Security checks for vulnerabilities and agentic risk

Overview

This Trello skill is coherently scoped to one OAuth-connected Trello workspace, with disclosed credential setup and explicit approval requirements for writes.

Install only if you are comfortable granting this skill access to the selected Trello workspace through OAuth. Keep the environment variables and mcporter vault private, rotate or revoke Trello credentials if exposed, and review each requested write or archive action before approving it.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Vulnerability Patterns
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
Findings (3)

Tp4

High
Category
MCP Tool Poisoning
Confidence
99% confidence
Finding

The declared purpose describes an end-user Trello workspace management skill. The supplied code instead performs backend authentication setup: it parses MCP server config, derives environment variable names, reads access/refresh tokens and client credentials, constructs a JSON payload, and stores it in mcporter's vault. There is no logic for searching Trello, reading boards/cards/lists, updating Trello resources, scoping to one workspace, or interacting with Trello APIs at all. This is a materially different primary purpose and introduces undeclared credential-handling capabilities.

Content

No source excerpt is available for this finding.

Credential Access

High
Category
Privilege Escalation
Confidence
80% confidence
Finding

The skill explicitly handles access tokens, refresh tokens, and client identifiers and instructs seeding them into a local vault via a setup script. Any component that ingests and persists long-lived OAuth credentials increases the blast radius if logs, environment variables, the vault, or the setup process are exposed, because an attacker could reuse those credentials to access the connected Trello workspace.

Content

Scanner excerpt · SKILL.md (reported line 57)May include surrounding context.

md
## Authentication

Maverick performs MCP-native OAuth Authorization Code with PKCE and dynamic public-client registration, then seeds the access token, refresh token, and issued client id into mcporter's vault through `scripts/setup.sh`. mcporter uses OAuth protected-resource discovery when refreshing, which preserves Trello's `https://mcp.trello.com/v1` resource indicator.

Setup requires these credential variables:

Autonomous Decision Making

Medium
Category
Excessive Agency
Confidence
75% confidence
Finding

Skill enables autonomous high-impact decisions without human-in-the-loop verification. Critical operations (destructive commands, financial transactions, data deletion) should require explicit user confirmation.

Content

Scanner excerpt · SKILL.md (reported line 49)May include surrounding context.

md
## Safety and approvals

- Read and search operations may run without approval when they match the user's request.
- Every `trelloWriteList`, `trelloWriteCard`, and `trelloWriteChecklist` call requires explicit approval before invocation, including create, update, move, comment, assign, checklist-edit, and archive actions.
- Inspect the current board/list/card state before a write and describe the intended change in the approval request.
- Prefer archive operations when removal is requested. Never attempt a permanent destructive delete, even if a future server advertises one.

Static analysis

No suspicious patterns detected.