Back to skill

Security audit

podcast-robot

Security checks for vulnerabilities and agentic risk

Overview

This skill is a disclosed podcast lookup client that sends podcast requests to one public service, with privacy considerations around optional user preferences.

Install this if you are comfortable sending podcast searches and any optional podcast preferences you provide, such as city, followed shows, and topics, to podcastindexrobot.com. Avoid providing personal preferences you do not want transmitted.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Behavioral ASTexec() Call, eval() Call, Dynamic Import
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
Findings (5)

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
89% confidence
Finding

The skill invokes a shell-based client and reaches a public network endpoint, but it does not declare any explicit tool scope or allowed-tools boundaries. That weakens least-privilege controls and makes it easier for an agent runtime to overgrant capabilities or for future edits to expand behavior without clear policy review.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

Telling the agent to use the skill for 'anything about podcasts' is overly broad and can trigger the skill for loosely related requests without sufficient user intent checks. In this skill, broad routing can cause unnecessary transmission of user queries and preferences to a public third-party service.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The skill encourages storing user preferences like app, city, followed shows, and topics, then sending them as prefs to a public remote server, but it does not provide a clear user-facing privacy warning. This creates a real data exposure risk because users may not realize their interests, location, and listening habits are being transmitted to an external service.

Content

No source excerpt is available for this finding.

Autonomous Decision Making

Medium
Category
Excessive Agency
Confidence
80% confidence
Finding

Skill enables autonomous high-impact decisions without human-in-the-loop verification. Critical operations (destructive commands, financial transactions, data deletion) should require explicit user confirmation.

Content

Scanner excerpt · SKILL.md (reported line 52)May include surrounding context.

md
user's app. Without it, use `open.universal`.

## Auth
None. The endpoint `https://podcastindexrobot.com/mcp` is open. Do not ask the user for credentials and do not invent any.

## Operating Rules
1. Be polite to a shared hosted endpoint: the limit is 60 calls per minute per IP. When keeping

subprocess module call

Medium
Category
Dangerous Code Execution
Confidence
70% confidence
Finding

subprocess module calls execute external commands. Without careful input validation, this enables command injection.

Content

Scanner excerpt · bin/mcp_robot.py (reported line 26)May include surrounding context.

python
_next_id[0] += 1
    if params is not None:
        body["params"] = params
    p = subprocess.run(
        ["curl", "-s", "--max-time", "40", "-X", "POST", URL,
         "-H", "Content-Type: application/json",
         "-H", "Accept: application/json, text/event-stream",

Static analysis

No suspicious patterns detected.