Back to skill

Security audit

Jewish Zmanim Calculator

Security checks for vulnerabilities and agentic risk

Overview

This Jewish-time calculator is purpose-aligned, but users should avoid the optional unpinned pip install and be aware of location-based API use.

Before installing, prefer running the bundled script without the pip install, or install dependencies only in an isolated environment with pinned versions. Provide city or coordinates intentionally, and do not rely on the advertised IP auto-detection unless the publisher documents how it works and asks for consent.

Vulnerability Patterns
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (1)

T08 · Insecure Dependencies

Warning
Location
SKILL.md:89
Finding

Unpinned and Unnecessary Third-Party Dependency Installation

Content
View full analysis

Vulnerability Details

File Location: SKILL.md, line 89
Vulnerability Type: Unpinned third-party dependencies
Risk Level: Medium

Vulnerable Code

bash
pip3 install hebcal-python python-dateutil

Technical Analysis

The installation instructions direct users to install hebcal-python and python-dateutil without version constraints or integrity hashes. Consequently, pip resolves mutable package releases and their transitive dependencies at installation time rather than installing a previously reviewed, reproducible dependency set.

If a package release, maintainer account, distribution channel, or transitive dependency is compromised, malicious package code could run during installation or later import. This risk is avoidable because the audited bundled script, scripts/zmanim.py, imports only Python standard-library modules and does not use either documented package.

No evidence was found that these packages are currently malicious. The finding concerns the unsafe and unnecessary dependency-installation practice.

Attack Path

  1. An attacker compromises a named package, one of its transitive dependencies, or the relevant package publishing account.
  2. The attacker publishes a malicious release that remains compatible with the unconstrained package names.
  3. A user follows the documented installation command.
  4. Pip resolves and downloads the attacker-controlled release because no reviewed version or hash is required.
  5. Malicious installation hooks or subsequently imported package code execute with the privileges of the user running pip.

Impact Assessment

Successful exploitation could execute arbitrary code with the invoking user's privileges. Depending on those privileges and the malicious package behavior, the affected scope could include user-accessible files, credentials, network resources, and the Python environment. The instruction does not itself request elevation, so admi ...[truncated 58 chars]

Remediation
View remediation

Remediation Suggestions

  1. Remove the dependency-installation instruction because the bundled script does not require these packages.
  2. If a separate supported workflow genuinely requires them, pin exact, reviewed versions.
  3. Lock all transitive dependencies and require verified hashes, such as through a requirements file used with pip install --require-hashes.
  4. Install dependencies inside an isolated virtual environment rather than the system Python environment.
  5. Use a trusted package index and periodically review pinned packages for known vulnerabilities.
  6. Clearly distinguish optional library integrations from the dependency-free bundled implementation.
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Rogue AgentSelf-Modification, Session Persistence
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
Findings (5)

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
93% confidence
Finding

The skill explicitly references network-dependent data sources and auto-location behavior, but it does not declare any tool scope or permissions to constrain that access. This creates a least-privilege and reviewability problem: the runtime may permit outbound requests without clear user or platform visibility into what destinations are contacted or what data is transmitted.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The trigger set includes broad terms like 'sunrise', 'sunset', and 'minyan', which can match ordinary conversation and cause the skill to activate unexpectedly. In a skill with network features and location handling, overbroad invocation increases the chance of unintended data use or confusing behavior even if the underlying functionality is legitimate.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

The quick-start text advertises automatic IP-based location detection for 'current location' without a clear privacy warning or consent step. IP geolocation discloses sensitive approximate location to external services and may surprise users who only asked for time calculations, making this a real privacy issue in context.

Content

No source excerpt is available for this finding.

Session Persistence

Medium
Category
Rogue Agent
Confidence
60% confidence
Finding

Skill establishes unauthorized persistence across sessions via cron jobs, startup scripts, or state files. Session persistence allows an attacker to maintain access beyond the current interaction.

Content

Scanner excerpt · SKILL.md (reported line 118)May include surrounding context.

Configuration

Create ~/.config/zmanim/default.json:

json
{
  "default_city": "Brooklyn, NY",

External Transmission

Medium
Category
Data Exfiltration
Confidence
60% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · scripts/zmanim.py (reported line 15)May include surrounding context.

python
import argparse

HEBCAL_API = "https://www.hebcal.com/hebcal"
GEONAMES_API = "http://api.geonames.org/searchJSON"

def get_coordinates(city):
    """Get lat/lon for a city."""

Static analysis

No suspicious patterns detected.