Back to skill

Security audit

Partycraft

Security checks for vulnerabilities and agentic risk

Overview

PartyCraft is a disclosed local event planner, but its bundled script can turn crafted event, task, guest, budget, or ID input into arbitrary Python code execution.

Review carefully before installing. The local storage behavior is disclosed and reasonable for an event planner, but the current script should not be used with untrusted or agent-supplied event text until the Python heredocs are fixed to pass values through arguments or JSON encoding instead of interpolating them into source code.

Vulnerability Patterns
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (1)

T09 · Insecure Skill Coding Practices

Error
Location
scripts/script.sh:18
Finding

Arbitrary Python Code Execution Through Unsafe Heredoc Interpolation

Content
View full analysis
Remediation
View remediation
Vulnerability Patterns
  • Rogue AgentSelf-Modification, Session Persistence
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
Findings (5)

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
92% confidence
Finding

The skill describes persistent local file writes to ~/.partycraft/events.json but does not declare any tool scope or permission boundary for that capability. Undeclared write access is risky because an agent could modify local state without explicit user or platform consent, and the persistence increases the chance of unintended data retention or tampering.

Content

No source excerpt is available for this finding.

Session Persistence

Medium
Category
Rogue Agent
Confidence
89% confidence
Finding

The skill intentionally stores event data, tasks, budgets, and guest information across sessions in a local JSON file. Session persistence becomes a security concern because the stored data may include sensitive personal information and remains on disk without any described retention controls, access restrictions, or user consent flow.

Content

Scanner excerpt · SKILL.md (reported line 21)May include surrounding context.

md
| `partycraft create <name> <date> [type]` | Create a new event. Types: `wedding`, `birthday`, `corporate`, `party`, `general` (default) |
| `partycraft list` | List all events with task progress, guest count, and budget |
| `partycraft budget <event_id> <amount>` | Set or update the budget for an event |
| `partycraft task <event_id> add <text>` | Add a task to an event |
| `partycraft task <event_id> done <number>` | Mark a task as complete by its number |
| `partycraft task <event_id> list` | List all tasks for an event with ✅/⬜ status |
| `partycraft guest <event_id> add <name>` | Add a guest to an event |

Session Persistence

Medium
Category
Rogue Agent
Confidence
80% confidence
Finding

Skill establishes unauthorized persistence across sessions via cron jobs, startup scripts, or state files. Session persistence allows an attacker to maintain access beyond the current interaction.

Content

Scanner excerpt · scripts/script.sh (reported line 248)May include surrounding context.

sh
echo "  create <name> <date> [type]  Create event (types: wedding/birthday/corporate/party/general)"
    echo "  list                         List all events"
    echo "  budget <id> <amount>         Set event budget"
    echo "  task <id> add <text>         Add task to event"
    echo "  task <id> done <number>      Mark task complete"
    echo "  task <id> list               List event tasks"
    echo "  guest <id> add <name>        Add guest"

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
91% confidence
Finding

The heading presents the skill as "活动策划助手" with no indication that users can choose their preferred language or locale. Under the policy, forcing a specific language without opt-in can be a natural-language policy violation, and this file does not document any user choice or region-specific justification.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
94% confidence
Finding

Line L002 labels the skill as "活动策划助手", which imposes a Chinese-language presentation choice in the user-facing description. The file does not indicate that the skill is region-specific or provide any opt-in or alternative language behavior, which matches the locale-policy concern for natural-language content.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.