Back to skill

Security audit

SXSW 2026 Schedule

Security checks for vulnerabilities and agentic risk

Overview

This skill is a local SXSW schedule lookup helper with disclosed public data use and no evidence of hidden access, persistence, or unsafe execution.

This appears safe to install from a security perspective. Users should know it relies on a bundled schedule snapshot plus optional web search for updates, and the CLI packaging may need a TypeScript runner rather than plain node as shown in the examples.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • YARA SignaturesMalware Match, Webshell Match, Cryptominer Match
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
Findings (37)

Ae1

High
Category
analysis-evasion
Content
files: ["scripts/sxsw.ts"]
Confidence
100% confidence
Finding
Referenced artifact was not completely inspected

Ae1

High
Category
analysis-evasion
Content
files: ["scripts/sxsw.ts"]
Confidence
100% confidence
Finding
Referenced artifact was not completely inspected

Ae1

High
Category
analysis-evasion
Content
files: ["scripts/sxsw.ts"]
Confidence
100% confidence
Finding
Referenced artifact was not completely inspected

Ae1

High
Category
analysis-evasion
Content
files: ["scripts/sxsw.ts"]
Confidence
100% confidence
Finding
Referenced artifact was not completely inspected

Ae1

High
Category
analysis-evasion
Content
files: ["scripts/sxsw.ts"]
Confidence
100% confidence
Finding
Referenced artifact was not completely inspected

Ae1

High
Category
analysis-evasion
Content
files: ["scripts/sxsw.ts"]
Confidence
100% confidence
Finding
Referenced artifact was not completely inspected

Ae1

High
Category
analysis-evasion
Content
files: ["scripts/sxsw.ts"]
Confidence
100% confidence
Finding
Referenced artifact was not completely inspected

Ae1

High
Category
analysis-evasion
Content
files: ["scripts/sxsw.ts"]
Confidence
100% confidence
Finding
Referenced artifact was not completely inspected

Ae1

High
Category
analysis-evasion
Content
files: ["scripts/sxsw.ts"]
Confidence
100% confidence
Finding
Referenced artifact was not completely inspected

Ae1

High
Category
analysis-evasion
Content
files: ["scripts/sxsw.ts"]
Confidence
100% confidence
Finding
Referenced artifact was not completely inspected

Ae1

High
Category
analysis-evasion
Content
files: ["scripts/sxsw.ts"]
Confidence
100% confidence
Finding
Referenced artifact was not completely inspected

Ae1

High
Category
analysis-evasion
Content
files: ["scripts/sxsw.ts"]
Confidence
100% confidence
Finding
Referenced artifact was not completely inspected

Ae1

High
Category
analysis-evasion
Content
files: ["scripts/sxsw.ts"]
Confidence
100% confidence
Finding
Referenced artifact was not completely inspected

Ae1

High
Category
analysis-evasion
Content
files: ["scripts/sxsw.ts"]
Confidence
100% confidence
Finding
Referenced artifact was not completely inspected

Ae1

High
Category
analysis-evasion
Content
files: ["scripts/sxsw.ts"]
Confidence
100% confidence
Finding
Referenced artifact was not completely inspected

Ae1

High
Category
analysis-evasion
Content
files: ["scripts/sxsw.ts"]
Confidence
100% confidence
Finding
Referenced artifact was not completely inspected

Ae1

High
Category
analysis-evasion
Content
files: ["scripts/sxsw.ts"]
Confidence
100% confidence
Finding
Referenced artifact was not completely inspected

Ae1

High
Category
analysis-evasion
Content
files: ["scripts/sxsw.ts"]
Confidence
100% confidence
Finding
Referenced artifact was not completely inspected

Ae1

High
Category
analysis-evasion
Content
| `data/sxsw-2026-schedule.json` | Local JSON | Complete schedule with 3,400+ events |
Confidence
100% confidence
Finding
Referenced artifact was not completely inspected

Ae1

High
Category
analysis-evasion
Content
| `data/sxsw-2026-index.json` | Local JSON | Search index (by date, track, venue, format, speaker, keyword) |
Confidence
100% confidence
Finding
Referenced artifact was not completely inspected

YARA rule 'agent_skill_mcp_tool_poisoning_metadata': MCP/tool metadata poisoning indicators in tool schemas or skill manifests [agent_skills]

High
Category
YARA Match
Content
{
  "scraped_at": "2026-02-26T03:00:06.272Z",
  "event_count": 3442,
  "date_range": {
    "start": "2026-03-12",
    "end": "2026-03-18"
  },
  "events": [
    {
      "id": "PP1150735",
      "title": "Jenn Whitmer Book Signing",
      "description": "Jenn Whitmer will be signing copies of “Joyosity” at the SXSW Bookstore.\r\r",
      "date": "",
      "start_time": "",
      "end_time": "",
      "venue": "",
      "venue_address": "",
      "venue_id": "",
      "track": "Workplace",
      "tags": [],
      "format": "Book Signing",
      "event_type": "Session",
      "speakers": [
        {
          "name": "Jenn Whitmer",
          "title": "CEO & Founder",
          "company": "Joyosity Works"
        }
      ],
      "credential_types": [
        "filmtv",
        "innovation",
        "music",
        "platinum"
Confidence
80% confidence
Finding
YARA rule matched a hack tool or exploit indicator (offensive tools, reconnaissance, privilege escalation, or exploit frameworks).

Vague Triggers

Medium
Confidence
91% confidence
Finding
The skill’s activation guidance is broader than necessary because it triggers on essentially any SXSW-related mention, not just clear schedule or event lookup requests. Over-broad activation can cause the agent to invoke this skill in loosely related conversations, increasing the chance of irrelevant tool use, unnecessary web-search fallback, and reduced adherence to least-privilege behavior.

YARA rule 'network_reconnaissance': Network reconnaissance and scanning patterns [hacktools]

Medium
Category
YARA Match
Content
"OE46415",
      "OE46825",
      "OE46423",
      "MS63734",
      "FS19410",
      "FS19411",
      "MS63749",
      "MS64227",
      "MS63822",
      "OE46826",
      "OE46424",
      "PP1162782",
      "MS64536",
      "MS64278",
      "MS63222",
      "MS63722",
      "OE46827",
      "OE46425",
      "PP1162236",
      "MS63400",
      "OE46828",
      "OE46426",
      "FS19412"
    ],
    "fiercely": [
      "MS63984",
      "MS64050",
      "MS63276",
      "MS63869",
      "MS64278",
      "MS63940",
      "MS63207",
      "MS63306"
    ],
    "vulnerable": [
      "MS63984",
      "PP1161937",
      "MS63568",
      "MS64053",
      "MS64617",
      "MS63276",
      "MS63788",
      "PP1162850",
      "MS63634",
      "MS63805",
      "MS63218",
      "MS63225",
      "PP1162364",
      "MS63773",
      "MS63152",
      "MS64278",
      "MS64128",
      "PP1162762",
      "FS19488",
      "PP1162429",
      "MS64017",
      "MS63200",
      "MS64510"
    ],
    "bad": [
Confidence
65% confidence
Finding
YARA rule matched a hack tool or exploit indicator (offensive tools, reconnaissance, privilege escalation, or exploit frameworks).

Natural-Language Policy Violations

Medium
Confidence
93% confidence
Finding
This JSON contains substantial Spanish-only natural-language content embedded directly in the indexed text, such as phrases beginning at L236006 and continuing through nearby entries. Because the file provides no indication that this locale is optional or limited to a justified region-specific context, it can violate the policy against forcing a specific language without user opt-in.

YARA rule 'network_reconnaissance': Network reconnaissance and scanning patterns [hacktools]

Medium
Category
YARA Match
Content
bnail_url": "https://images.sxsw.com/Cl9winBVGmlc3zvjA27Hgaj5XlE=/450x450/images.sxsw.com/195/43db329e-859f-b4aa-3e2c-76655ef6ccaf/artist-76093"
    },
    {
      "id": "MS63984",
      "title": "Wilby",
      "description": "Jersey-born Maria Crawford has been paving her way through the Nashville independent music scene since 2014. Now Brooklyn-based, she continues to capture listeners with her fiercely vulnerable songwriting and compelling live performances. Wilby’s debut single “Bad” (2020) gained immediate attention, followed by \"Translucent Beauty” (2021), drifting between bedroom pop and indie rock. Her sophomore EP, “Happiest Woman” (2023), marked a shift toward showcasing a full-band production, mirroring the force of Wilby’s live sound. Wilby’s debut album, “Center of Affection” (2025, via Hit the North Records), explores both the cathartic side of indie-rock and the vulnerable side of twangy folk. Wilby has been featured in FLOOD Magazine, Luna Collectiv
Confidence
65% confidence
Finding
YARA rule matched a hack tool or exploit indicator (offensive tools, reconnaissance, privilege escalation, or exploit frameworks).

Static analysis

Detected: suspicious.install_untrusted_source

Install source points to URL shortener or raw IP.

Warn
Code
suspicious.install_untrusted_source
Location
data/sxsw-2026-schedule.json:100264