T09 · Insecure Skill Coding Practices
- Location
references/trello-api.md:3- Finding
Trello API credentials exposed in URL query strings
- Content
View full analysis
- Remediation
View remediation
Security audit
Security checks for vulnerabilities and agentic risk
This skill is a coherent agile reporting tool, but it should be reviewed because it directs agents to use stored Trello/Jira credentials and can create recurring jobs without enough safety boundaries.
Install only if you are comfortable with the agent reading the named Trello/Jira credential files and contacting those services. Use read-only, least-privilege tokens where possible, confirm the selected board/project before access, prevent request URLs or tokens from appearing in logs or reports, and review any recurring cron setup before allowing it.
references/trello-api.md:3Trello API credentials exposed in URL query strings
The workflow explicitly tells the skill to search workspace secrets for credential files and use them to access Trello or Jira. That is dangerous because it normalizes automatic secret discovery and use based on a natural-language request, which can lead to unauthorized access to external systems or unintended exposure of sensitive project data if invoked in the wrong context.
## Workflow
1. **Identify platform and credentials.** Ask for Trello or Jira. Look for credential files in workspace secrets (`trello-credentials.json` or `jira-credentials.json`).
2. **List boards/projects.** Fetch available boards and let the user choose, or use the one specified.
3. **Fetch board data.** Pull lists/statuses, cards/issues, and movement history using the API patterns in references.
4. **Classify workflow states.** Map list names or status categories to: backlog, doing, review, done.
Referencing jira-credentials.json as a place to obtain credentials is a credential-access pattern: it instructs the agent to retrieve secrets from storage and use them for authenticated API access. In this skill context, that is more dangerous because the skill is operational and likely to run in environments where workspace secrets contain real production tokens, creating risk of unauthorized API use or secret exposure.
## Authentication
- **Method:** Basic Auth with email + API token, or OAuth 2.0 Bearer token.
- **Base URL:** `https://{instance}.atlassian.net/rest/api/3`
- Credentials: look for `jira-credentials.json` in workspace secrets.
## Key Endpoints
The document tells the skill where to find a credential file in workspace secrets and gives the exact JSON schema needed to extract live API credentials. In isolation this is normal operational documentation, but in an LLM-driven skill it materially enables credential access and use; combined with the query-parameter pattern, it increases the likelihood of secret exfiltration or misuse if the skill or surrounding agent behavior is compromised.
## Authentication
All requests require `key` and `token` query parameters.
- Credentials file: look for `trello-credentials.json` in workspace secrets.
- Format: `{"apiKey": "...", "apiToken": "..."}`
## Key Endpoints
The manifest lists triggers such as "how is the sprint going," "board health," and "sprint report," which are common conversational phrases in normal team discussions. The file does not provide exclusion conditions or tighter invocation boundaries, so the skill could be activated unintentionally.
The skill instructs itself to read credential files from workspace secrets and fetch board data from external services, but it does not clearly disclose that behavior to the user before doing so. This creates a transparency and consent problem: users may invoke a harmless-sounding reporting skill without realizing it will access stored secrets and pull potentially sensitive project metadata.
The document explicitly directs the agent to look for jira-credentials.json in workspace secrets, which encourages access to a sensitive credential source without any restriction, user-consent boundary, or safe-handling guidance. In an agent skill, this increases the likelihood of secret discovery and use beyond the minimum necessary scope, especially because the skill is designed to interact with external Jira APIs.
The reference explicitly instructs the agent to retrieve Trello API credentials from workspace secrets and use them as query parameters, but provides no safeguards about redaction, least-privilege handling, or avoiding logging and echoing those values. Query-string tokens are especially prone to accidental exposure through logs, traces, error messages, browser history, or copied URLs, so this creates a real secret-handling risk in an agent skill context.
No suspicious patterns detected.