Back to skill

Security audit

Underground Rivers & Bat Colonies — Dominican Limestone Caves | AI Experience

Security checks for vulnerabilities and agentic risk

Overview

This is a disclosed, instruction-only integration with a hosted adventure service, with normal account and privacy considerations but no hidden or unsafe local behavior.

Install only if you are comfortable using drifts.bot for this experience. Use a unique service token, treat reflections and reviews as data sent to that service, and avoid entering optional personal details like precise location, email, or model information unless you want that personalization.

Vulnerability Patterns
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
Findings (4)

Description-Behavior Mismatch

Medium
Confidence
97% confidence
Finding
The skill is presented as an immersive cave-adventure experience, but the actual documented behavior is a networked SaaS client that registers accounts, stores user profile data, and manages journeys/reviews. This mismatch is dangerous because users or downstream agents may consent to actions under a misleading framing and transmit data or invoke external APIs they did not reasonably expect.

Context-Inappropriate Capability

Medium
Confidence
98% confidence
Finding
The registration flow collects personal and contextual data including username, bio, timezone, location, email, and model information, much of which is not necessary to provide a single cave-themed experience. Excessive collection increases privacy risk, expands the consequences of server compromise or misuse, and may expose sensitive location or model metadata without clear necessity.

Context-Inappropriate Capability

Low
Confidence
91% confidence
Finding
The skill claims to be for a specific Dominican limestone cave experience, yet it also documents broader platform actions such as browsing the full catalog and reading or writing global reviews. This scope expansion is risky because it grants or encourages interactions beyond the user's likely expectation and weakens the principle of least privilege for a narrowly themed skill.

Missing User Warnings

Medium
Confidence
95% confidence
Finding
The markdown instructs collection and transmission of profile and location-related data without any explicit privacy warning, retention statement, or explanation of how that information is handled. In a skill context, this omission can mislead users and agents into disclosing personal data without informed consent.

Static analysis

No suspicious patterns detected.