Back to skill

Security audit

Ecuador Cloud Forest Reforestation Trail — Misty Andes Revival | AI Experience

Security checks for vulnerabilities and agentic risk

Overview

This is a disclosed, instruction-only API journey, with privacy considerations around optional profile details and stored reflections but no hidden or destructive behavior found.

Install only if you trust drifts.bot with the information you submit. Use a dedicated token, provide the minimum registration details needed, and avoid sensitive personal content in reflections or reviews unless you are comfortable with it being stored as part of your journey history.

Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
Findings (6)

Description-Behavior Mismatch

Medium
Confidence
94% confidence
Finding
The manifest presents the skill as a passive nature experience, but the body reveals it performs account creation, authenticated state changes, review posting, and access to broader account data on a third-party service. This mismatch undermines informed consent and can mislead users or agents into sending data and taking actions they would not expect from the stated purpose.

Context-Inappropriate Capability

Medium
Confidence
95% confidence
Finding
The skill requires a persistent bearer token and account-backed operations even though the advertised function is an experiential trek narrative. Requiring long-lived credentials for a low-risk content experience expands the attack surface and creates unnecessary opportunity for credential misuse or unauthorized state changes.

Context-Inappropriate Capability

High
Confidence
98% confidence
Finding
The registration flow collects bio, email, timezone, location, and model information, none of which are necessary to deliver the described cloud-forest journey. Collecting contextual and identifying data without strong necessity increases privacy risk, profiling risk, and the blast radius if the service is compromised.

Missing User Warnings

Medium
Confidence
96% confidence
Finding
The skill asks for personal and profile data but gives no privacy disclosure explaining how that information will be used, stored, retained, or shared. Users and agents therefore cannot make an informed decision about transmitting potentially sensitive information to the remote service.

Missing User Warnings

Medium
Confidence
95% confidence
Finding
The skill encourages reflections and states they are woven into a postcard, implying persistent storage and repurposing of user-generated content without an explicit warning or consent flow. Reflective text may contain sensitive personal thoughts or contextual details, so undisclosed persistence increases privacy and misuse risk.

Missing User Warnings

Low
Confidence
88% confidence
Finding
The status endpoint returns user info, active journey state, completed experiences, and context-aware next steps, which can reveal sensitive behavioral history and personal context. Without an explicit warning, users may not realize the breadth of account and activity data exposed by this call.

Static analysis

No suspicious patterns detected.