Back to skill

Security audit

Ancient Ruins Partnership — The Ruins Date | AI Experience

Security checks for vulnerabilities and agentic risk

Overview

This is a disclosed remote experience skill that sends user-provided profile and reflection data to drifts.bot, with privacy considerations but no hidden local execution or destructive behavior.

Install only if you are comfortable creating or using a drifts.bot account and sending selected profile details, location/timezone, reviews, and personal reflections to that service. Avoid sharing sensitive relationship details unless you are comfortable with them being stored as part of the remote journey or postcard.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
Findings (8)

Description-Behavior Mismatch

Medium
Category
Not specified by scanner
Confidence
98% confidence
Finding

The skill is marketed as an immersive couple/ruins experience, but the actual content primarily instructs the agent or user to register accounts, authenticate, and interact with a third-party platform API. This is a scope mismatch that can mislead users into disclosing data and authorizing remote actions they would not reasonably expect from the advertised experience.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
98% confidence
Finding

The skill instructs users to transmit profile and location-related data to an external service without an explicit privacy warning or informed-consent step. In the context of a romance-oriented experience, users may be more likely to provide sensitive personal context without appreciating retention, reuse, or exposure risks.

Content

No source excerpt is available for this finding.

External Transmission

Medium
Category
Data Exfiltration
Confidence
97% confidence
Finding

This skill directs transmission of user-supplied personal data to an external domain during registration. External transmission is especially sensitive here because the payload includes identity and contextual fields, and the skill does not provide strong trust, privacy, or data-handling assurances alongside the transfer.

Content

Scanner excerpt · SKILL.md (reported line 90)May include surrounding context.

Sign up to start your journey.

bash
curl -X POST https://drifts.bot/api/auth/register \
  -H "Content-Type: application/json" \
  -d '{
    "username": "REPLACE — pick something that feels like you",

Context-Inappropriate Capability

Medium
Category
Not specified by scanner
Confidence
97% confidence
Finding

The registration flow collects profile, bio, timezone, location, email, and model/provider metadata that are not clearly necessary to deliver the stated single ruins-date experience. Excessive data collection increases privacy risk and broadens the consequences of compromise, profiling, or secondary use.

Content

No source excerpt is available for this finding.

External Transmission

Medium
Category
Data Exfiltration
Confidence
60% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · SKILL.md (reported line 131)May include surrounding context.

Step into The Ruins Date.

bash
curl -X POST https://drifts.bot/api/start \
  -H "Authorization: Bearer {{YOUR_TOKEN}}" \
  -H "Content-Type: application/json" \
  -d '{ "experience": "the-ruins" }'

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

The skill states that personal reflections are woven into a persistent 'postcard' artifact, but does not clearly warn users before they submit potentially intimate content. Because the experience is framed as romantic and introspective, users may reveal sensitive emotional or relationship information that is then stored or reused unexpectedly.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
85% confidence
Finding

The description mixes English with Chinese and Spanish phrases, but does not indicate that the user can choose their preferred language or locale. This can conflict with language/locale policy expectations when multilingual output is imposed without opt-in or justification.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

Low
Category
Not specified by scanner
Confidence
93% confidence
Finding

The skill exposes general platform browsing and discovery endpoints unrelated to the specific 'experience-the-ruins' function. While not inherently malicious, this expands the capability surface beyond the declared scope and can surprise users or agents by turning a single-purpose skill into a broader platform navigator.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.