Back to skill

Security audit

Agile Observer

Security checks for vulnerabilities and agentic risk

Overview

This skill is a coherent agile reporting tool, but it should be reviewed because it directs agents to use stored Trello/Jira credentials and can create recurring jobs without enough safety boundaries.

Install only if you are comfortable with the agent reading the named Trello/Jira credential files and contacting those services. Use read-only, least-privilege tokens where possible, confirm the selected board/project before access, prevent request URLs or tokens from appearing in logs or reports, and review any recurring cron setup before allowing it.

Vulnerability Patterns
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (1)

T09 · Insecure Skill Coding Practices

Warning
Location
references/trello-api.md:3
Finding

Trello API credentials exposed in URL query strings

Content
View full analysis
Remediation
View remediation
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (7)

Credential Access

High
Category
Privilege Escalation
Confidence
95% confidence
Finding

The workflow explicitly tells the skill to search workspace secrets for credential files and use them to access Trello or Jira. That is dangerous because it normalizes automatic secret discovery and use based on a natural-language request, which can lead to unauthorized access to external systems or unintended exposure of sensitive project data if invoked in the wrong context.

Content

Scanner excerpt · SKILL.md (reported line 13)May include surrounding context.

md
## Workflow

1. **Identify platform and credentials.** Ask for Trello or Jira. Look for credential files in workspace secrets (`trello-credentials.json` or `jira-credentials.json`).
2. **List boards/projects.** Fetch available boards and let the user choose, or use the one specified.
3. **Fetch board data.** Pull lists/statuses, cards/issues, and movement history using the API patterns in references.
4. **Classify workflow states.** Map list names or status categories to: backlog, doing, review, done.

Credential Access

High
Category
Privilege Escalation
Confidence
96% confidence
Finding

Referencing jira-credentials.json as a place to obtain credentials is a credential-access pattern: it instructs the agent to retrieve secrets from storage and use them for authenticated API access. In this skill context, that is more dangerous because the skill is operational and likely to run in environments where workspace secrets contain real production tokens, creating risk of unauthorized API use or secret exposure.

Content

Scanner excerpt · references/jira-api.md (reported line 6)May include surrounding context.

md
## Authentication
- **Method:** Basic Auth with email + API token, or OAuth 2.0 Bearer token.
- **Base URL:** `https://{instance}.atlassian.net/rest/api/3`
- Credentials: look for `jira-credentials.json` in workspace secrets.

## Key Endpoints

Credential Access

High
Category
Privilege Escalation
Confidence
95% confidence
Finding

The document tells the skill where to find a credential file in workspace secrets and gives the exact JSON schema needed to extract live API credentials. In isolation this is normal operational documentation, but in an LLM-driven skill it materially enables credential access and use; combined with the query-parameter pattern, it increases the likelihood of secret exfiltration or misuse if the skill or surrounding agent behavior is compromised.

Content

Scanner excerpt · references/trello-api.md (reported line 5)May include surrounding context.

md
## Authentication
All requests require `key` and `token` query parameters.
- Credentials file: look for `trello-credentials.json` in workspace secrets.
- Format: `{"apiKey": "...", "apiToken": "..."}`

## Key Endpoints

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The manifest lists triggers such as "how is the sprint going," "board health," and "sprint report," which are common conversational phrases in normal team discussions. The file does not provide exclusion conditions or tighter invocation boundaries, so the skill could be activated unintentionally.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
89% confidence
Finding

The skill instructs itself to read credential files from workspace secrets and fetch board data from external services, but it does not clearly disclose that behavior to the user before doing so. This creates a transparency and consent problem: users may invoke a harmless-sounding reporting skill without realizing it will access stored secrets and pull potentially sensitive project metadata.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The document explicitly directs the agent to look for jira-credentials.json in workspace secrets, which encourages access to a sensitive credential source without any restriction, user-consent boundary, or safe-handling guidance. In an agent skill, this increases the likelihood of secret discovery and use beyond the minimum necessary scope, especially because the skill is designed to interact with external Jira APIs.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

The reference explicitly instructs the agent to retrieve Trello API credentials from workspace secrets and use them as query parameters, but provides no safeguards about redaction, least-privilege handling, or avoiding logging and echoing those values. Query-string tokens are especially prone to accidental exposure through logs, traces, error messages, browser history, or copied URLs, so this creates a real secret-handling risk in an agent skill context.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.