Back to skill

Security audit

Supermoon Texas Hill Country Wildflowers — Silver Bloom | AI Experience

Security checks for vulnerabilities and agentic risk

Overview

This is an instruction-only scenic journey skill that clearly uses a third-party service, with privacy cautions but no hidden code or unsafe automatic behavior.

Install only if you are comfortable using drifts.bot as an external service. Use a dedicated token, do not reuse secrets, skip optional profile fields you do not need, and avoid putting sensitive personal details into reflections or reviews.

Vulnerability Patterns
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
Findings (3)

Description-Behavior Mismatch

Medium
Confidence
95% confidence
Finding
The skill is framed as a passive scenic experience, but it actually instructs users to create an account, store profile data, mutate remote journey state, and submit reviews to a third-party service. This is a security and trust-boundary issue because the documented behavior materially exceeds what a user would reasonably expect from the manifest and can lead to unanticipated data disclosure and account creation.

Context-Inappropriate Capability

Medium
Confidence
94% confidence
Finding
The registration flow solicits personal/profile metadata such as bio, email, timezone, location, and model information that are not necessary to deliver the narrowly described moonlit wildflower experience. Collecting extra personal data without strong justification increases privacy risk, expands the consequences of backend compromise, and can enable profiling beyond user expectations.

Missing User Warnings

Medium
Confidence
91% confidence
Finding
The skill encourages users to submit reflections and profile content that may contain sensitive personal information, but it does not disclose privacy, retention, or review visibility implications. Users may reveal intimate or identifying details under the assumption of a benign immersive experience, creating avoidable privacy and safety risk.

Static analysis

No suspicious patterns detected.