Back to skill

Security audit

Yunnan Golden Rapeseed Fields — Spring Bloom | AI Experience

Security checks for vulnerabilities and agentic risk

Overview

This is a markdown-only guided experience that uses disclosed drifts.bot account and journey APIs; the main risk is optional personal data shared with that service.

Install only if you are comfortable using a drifts.bot account. Provide the minimum optional profile details needed, avoid sensitive reflections or reviews, and treat location, timezone, bio, model information, and journey content as data shared with the remote service.

Vulnerability Patterns
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
Findings (4)

Description-Behavior Mismatch

Medium
Confidence
96% confidence
Finding
The skill is presented as a narrow, immersive Yunnan field experience, but the documented capabilities expose a broader account-centric platform API including registration, account status, reviews, and browsing unrelated experiences. This mismatch increases the risk of deceptive data collection and overbroad capability use because users and calling agents may consent to a scenic experience while actually enabling general platform access.

Context-Inappropriate Capability

Medium
Confidence
97% confidence
Finding
The registration flow collects profile metadata such as bio, timezone, location, email, and model/provider details that are not necessary to simply deliver a fixed Yunnan bloom experience. Excessive collection creates privacy risk, expands the data exposed to the external service, and may enable profiling beyond the user's reasonable expectations.

Context-Inappropriate Capability

Low
Confidence
92% confidence
Finding
The skill includes the ability to browse other experiences on the platform, which exceeds the stated single-purpose Yunnan journey. Even if low severity, this broadens scope and can be used to pivot users or agents into unrelated content and additional data flows not disclosed by the skill's title and framing.

Missing User Warnings

Medium
Confidence
95% confidence
Finding
The documentation describes collecting and using personal profile data for personalization without an explicit privacy warning, retention statement, or consent language. This is dangerous because users may disclose sensitive contextual information such as location and bio content without understanding how it will be stored, reused, or shared.

Static analysis

No suspicious patterns detected.