Back to skill

Security audit

Aurora Borealis Solar Storm — Lake Superior Hunt | AI Experience

Security checks for vulnerabilities and agentic risk

Overview

This is a markdown-only skill for a hosted drifts.bot narrative experience, with disclosed account/API use and privacy considerations but no hidden code or destructive behavior.

Install only if you trust drifts.bot and want a hosted account-based narrative journey. Use a token created for this service only, provide the minimum optional profile data, and avoid sensitive reflections or reviews unless you are comfortable with them being stored remotely.

Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
Findings (3)

Description-Behavior Mismatch

Medium
Confidence
96% confidence
Finding
The skill markets itself as an immersive aurora-field/scientific activity, but the actual behavior is a remote account-based experience platform with registration, journey state, reviews, and browsing. This mismatch can mislead users and downstream agents into disclosing data or invoking network actions they would not expect from the stated purpose, undermining informed consent and safe tool use.

Context-Inappropriate Capability

Medium
Confidence
94% confidence
Finding
The registration flow solicits bio, timezone, location, email, and model information that are not necessary to start a simple aurora-themed journey. Excessive collection increases privacy risk, enables profiling, and creates unnecessary exposure if the remote service is compromised or repurposes the data.

Missing User Warnings

Medium
Confidence
97% confidence
Finding
The skill instructs users/agents to send personal profile data to an external API without an explicit privacy warning, consent flow, or data handling disclosure. This is dangerous because agents may transmit sensitive contextual data automatically, and users are not given enough information to assess the privacy consequences.

Static analysis

No suspicious patterns detected.