Back to skill

Security audit

Trello Planner

Security checks for vulnerabilities and agentic risk

Overview

The skill is read-only and Trello-focused, but it asks for sensitive Trello credentials while using broad board enumeration, non-expiring token guidance, and several overstated or unsupported security/capability claims.

Install only if you are comfortable giving the skill read access to Trello data visible to the supplied token, including board names. Prefer a read-only token with the shortest practical expiration, avoid sharing full Trello URLs containing key or token values, pass an explicit board_id for sensitive workspaces, and treat the advertised optimization/search/capacity features as overstated unless the implementation is updated.

Vulnerability Patterns
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (2)

T09 · Insecure Skill Coding Practices

Warning
Location
skill.js:29
Finding

Trello credentials exposed through URL query parameters

Content
View full analysis
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Note
Location
skill.js:38
Finding

Missing outbound request timeout contrary to documented security controls

Content
View full analysis
Remediation
View remediation
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
Findings (7)

Tp4

High
Category
MCP Tool Poisoning
Confidence
95% confidence
Finding

The skill is not doing anything obviously unsafe or write-capable, and it remains within Trello’s API using read-only style access. However, the declared description overstates and partly misstates the actual behavior. The implementation’s primary behavior is a narrow board-health check: list accessible boards via /members/me/boards, select one board, fetch its cards, count open and overdue cards, and return a basic insight/health score. That differs materially from the declared coverage of lists/cards/members via /boards/{id}/*, cross-board search, and richer planning features like sprint capacity and optimization. Additionally, it accesses a resource outside the declared endpoint list (/members/me/boards).

Content

No source excerpt is available for this finding.

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
91% confidence
Finding

The skill declares network-dependent behavior and requires API credentials, but does not define an explicit tool scope such as allowed-tools or permissions. That creates an authorization ambiguity where a user-invocable skill may be granted broader runtime capabilities than intended, increasing the chance of unintended outbound requests or future abuse if the implementation changes.

Content

No source excerpt is available for this finding.

External Transmission

Medium
Category
Data Exfiltration
Confidence
84% confidence
Finding

The skill includes a test URL that embeds the API key and token in a query string. Even though this targets the legitimate Trello API, placing secrets in URLs is dangerous because they can leak via browser history, logs, screenshots, proxies, referrers, or copied command output.

Content

Scanner excerpt · SKILL.md (reported line 41)May include surrounding context.

text
1. https://trello.com/app-key → API Key
2. https://trello.com/1/authorize?key=[YOUR_KEY]&name=TrelloPlanner&scope=read&expiration=never → Token  
3. Test: https://api.trello.com/1/members/me/boards?key=[KEY]&token=[TOKEN]

Verified Endpoints (Boards Group)

External Transmission

Medium
Category
Data Exfiltration
Confidence
60% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · skill.js (reported line 11)May include surrounding context.

js
* - No credential logging or persistence
 */

const TRELLO_API_BASE = "https://api.trello.com/1";
const TRELLO_DOMAIN = "api.trello.com";

/**

Description-Behavior Mismatch

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The skill metadata says it is limited to board read endpoints under /boards/{id}/*, but the implementation also calls /members/me/boards to enumerate all boards available to the authenticated user. This creates a scope/behavior mismatch that can expose additional account-level metadata and undermine user trust and permission review.

Content

No source excerpt is available for this finding.

Scope Creep

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The code accesses member-scoped board listing data beyond the endpoints described in the skill metadata, which states only /boards/{id}/lists, /cards, and /members are used. Even though the Trello token is read-only, enumerating a user's boards reveals additional organizational and project information not clearly disclosed by the skill contract.

Content

No source excerpt is available for this finding.

Vague Triggers

Low
Category
Not specified by scanner
Confidence
84% confidence
Finding

The skill is user-invocable via slash commands but does not clearly constrain what inputs, targets, or operating scope are permitted. In practice, underspecified invocation scope can cause the agent to act on ambiguous user requests, fetch broader board data than expected, or mishandle sensitive workspace context.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.