Back to skill

Security audit

Navier-Stokes Turbulence — Millennium: Navier-Stokes | AI Experience

Security checks for vulnerabilities and agentic risk

Overview

This looks like a learning skill, but it also asks an agent to use broader platform account, profile, discovery, and personal-data flows that are not clearly scoped to the Navier-Stokes lesson.

Install only if you are comfortable creating or using an external platform account and sharing profile details with that service. Prefer providing only required fields, avoid optional personal details like location or bio, and make sure the agent asks before browsing unrelated experiences or changing profile/account state.

Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
Findings (4)

Description-Behavior Mismatch

Medium
Confidence
91% confidence
Finding
The skill is presented as a narrowly scoped educational experience about Navier-Stokes, but the documented behavior includes generic platform account creation, profile management, reviews, status, and broader journey operations. This scope mismatch can mislead users and agents into authorizing actions and data sharing beyond what is necessary for the claimed purpose, increasing the risk of unnecessary data exposure and unintended platform interaction.

Context-Inappropriate Capability

Medium
Confidence
90% confidence
Finding
The skill includes catalog browsing for unrelated experiences, which exceeds the user's expected task of engaging with a specific Navier-Stokes experience. This creates unnecessary expansion of authority and can be used to steer users or agents into unrelated content and additional API interactions not justified by the skill's stated purpose.

Context-Inappropriate Capability

Medium
Confidence
95% confidence
Finding
The registration flow requests personal profile attributes including bio, email, timezone, location, and model information that are not necessary to deliver a basic physics-learning experience. Collecting excess personal and environment data broadens privacy risk, creates avoidable sensitive profiling, and increases harm if the external service is compromised or misuses the information.

Missing User Warnings

Medium
Confidence
93% confidence
Finding
The skill asks users to submit personal profile data to an external service without providing a clear privacy warning, retention notice, or explanation of handling practices. This undermines informed consent and can lead users or agents to disclose personal information without understanding the privacy consequences.

Static analysis

No suspicious patterns detected.