Back to skill

Security audit

Jadwal Sholat

Security checks for vulnerabilities and agentic risk

Overview

This skill is a disclosed Indonesian prayer-time helper that calls a relevant public API and does not show hidden persistence, credential access, or destructive behavior.

Install only if you are comfortable sending prayer-time lookup inputs such as city or location ID, date/month, and timezone to api.myquran.com. Expect Indonesian-language output and note that monthly results are presented as a seven-day preview in the helper script.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
Findings (10)

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
90% confidence
Finding

The skill documents and encourages network access to an external API but does not declare any explicit tool scope such as allowed-tools or permissions. This creates a governance gap: an agent may use broader network capabilities than intended, making review, enforcement, and least-privilege controls weaker. In this context the endpoint appears legitimate and the skill purpose requires network use, so the issue is configuration-related rather than overtly malicious.

Content

No source excerpt is available for this finding.

External Transmission

Medium
Category
Data Exfiltration
Confidence
60% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · SKILL.md (reported line 9)May include surrounding context.

md
import urllib.request
from typing import Any, Dict, List, Optional, Tuple

API_BASE = "https://api.myquran.com/v3"
DEFAULT_TZ = "Asia/Jakarta"

External Transmission

Medium
Category
Data Exfiltration
Confidence
60% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · SKILL.md (reported line 52)May include surrounding context.

md
import urllib.request
from typing import Any, Dict, List, Optional, Tuple

API_BASE = "https://api.myquran.com/v3"
DEFAULT_TZ = "Asia/Jakarta"

External Transmission

Medium
Category
Data Exfiltration
Confidence
60% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · SKILL.md (reported line 58)May include surrounding context.

md
import urllib.request
from typing import Any, Dict, List, Optional, Tuple

API_BASE = "https://api.myquran.com/v3"
DEFAULT_TZ = "Asia/Jakarta"

External Transmission

Medium
Category
Data Exfiltration
Confidence
60% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · SKILL.md (reported line 65)May include surrounding context.

md
import urllib.request
from typing import Any, Dict, List, Optional, Tuple

API_BASE = "https://api.myquran.com/v3"
DEFAULT_TZ = "Asia/Jakarta"

External Transmission

Medium
Category
Data Exfiltration
Confidence
60% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · SKILL.md (reported line 68)May include surrounding context.

md
import urllib.request
from typing import Any, Dict, List, Optional, Tuple

API_BASE = "https://api.myquran.com/v3"
DEFAULT_TZ = "Asia/Jakarta"

External Transmission

Medium
Category
Data Exfiltration
Confidence
60% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · scripts/myquran_sholat.py (reported line 27)May include surrounding context.

python
import urllib.request
from typing import Any, Dict, List, Optional, Tuple

API_BASE = "https://api.myquran.com/v3"
DEFAULT_TZ = "Asia/Jakarta"

Description-Behavior Mismatch

Medium
Category
Not specified by scanner
Confidence
97% confidence
Finding

The manifest says the skill can provide jadwal sholat for '1 bulan', which implies the full month's schedule. However, the monthly command intentionally prints only the first 7 days and labels it as a preview, so the implemented behavior is narrower than the advertised capability.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
93% confidence
Finding

The module docstring and command descriptions are entirely in Indonesian, and the CLI later prints only Indonesian messages. Under the policy, forcing a specific language without user opt-in can be a natural-language policy violation unless the locale constraint is explicitly documented and justified.

Content

No source excerpt is available for this finding.

Intent-Code Divergence

Low
Category
Not specified by scanner
Confidence
95% confidence
Finding

The docstring documents commands 'id-tanggal' and 'id-bulan', but the parser actually implements a single 'id-period' command instead. This is an active documentation-to-code mismatch that can mislead callers about the supported interface.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.