T09 · Insecure Skill Coding Practices
- Location
skill.js:29- Finding
Trello credentials exposed through URL query parameters
- Content
View full analysis
- Remediation
View remediation
Security audit
Security checks for vulnerabilities and agentic risk
The skill is read-only and Trello-focused, but it asks for sensitive Trello credentials while using broad board enumeration, non-expiring token guidance, and several overstated or unsupported security/capability claims.
Install only if you are comfortable giving the skill read access to Trello data visible to the supplied token, including board names. Prefer a read-only token with the shortest practical expiration, avoid sharing full Trello URLs containing key or token values, pass an explicit board_id for sensitive workspaces, and treat the advertised optimization/search/capacity features as overstated unless the implementation is updated.
skill.js:29Trello credentials exposed through URL query parameters
skill.js:38Missing outbound request timeout contrary to documented security controls
The skill is not doing anything obviously unsafe or write-capable, and it remains within Trello’s API using read-only style access. However, the declared description overstates and partly misstates the actual behavior. The implementation’s primary behavior is a narrow board-health check: list accessible boards via /members/me/boards, select one board, fetch its cards, count open and overdue cards, and return a basic insight/health score. That differs materially from the declared coverage of lists/cards/members via /boards/{id}/*, cross-board search, and richer planning features like sprint capacity and optimization. Additionally, it accesses a resource outside the declared endpoint list (/members/me/boards).
The skill declares network-dependent behavior and requires API credentials, but does not define an explicit tool scope such as allowed-tools or permissions. That creates an authorization ambiguity where a user-invocable skill may be granted broader runtime capabilities than intended, increasing the chance of unintended outbound requests or future abuse if the implementation changes.
The skill includes a test URL that embeds the API key and token in a query string. Even though this targets the legitimate Trello API, placing secrets in URLs is dangerous because they can leak via browser history, logs, screenshots, proxies, referrers, or copied command output.
1. https://trello.com/app-key → API Key
2. https://trello.com/1/authorize?key=[YOUR_KEY]&name=TrelloPlanner&scope=read&expiration=never → Token
3. Test: https://api.trello.com/1/members/me/boards?key=[KEY]&token=[TOKEN]
Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.
* - No credential logging or persistence
*/
const TRELLO_API_BASE = "https://api.trello.com/1";
const TRELLO_DOMAIN = "api.trello.com";
/**
The skill metadata says it is limited to board read endpoints under /boards/{id}/*, but the implementation also calls /members/me/boards to enumerate all boards available to the authenticated user. This creates a scope/behavior mismatch that can expose additional account-level metadata and undermine user trust and permission review.
The code accesses member-scoped board listing data beyond the endpoints described in the skill metadata, which states only /boards/{id}/lists, /cards, and /members are used. Even though the Trello token is read-only, enumerating a user's boards reveals additional organizational and project information not clearly disclosed by the skill contract.
The skill is user-invocable via slash commands but does not clearly constrain what inputs, targets, or operating scope are permitted. In practice, underspecified invocation scope can cause the agent to act on ambiguous user requests, fetch broader board data than expected, or mishandle sensitive workspace context.
No suspicious patterns detected.