Back to skill

Security audit

Wrike

Security checks for vulnerabilities and agentic risk

Overview

This Wrike skill is broad and powerful, but its sensitive access and automation behavior are clearly disclosed and tied to its stated purpose.

Install only if you intend to let an agent operate through your Maton-connected Wrike account. Use read-only and narrow OAuth scopes where possible, confirm every write/admin/export/automation action, avoid third-party trigger destinations unless you understand the ongoing data flow, and delete unused connections, functions, triggers, and destinations.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Vulnerability Patterns
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
Findings (2)

Description-Behavior Mismatch

Medium
Category
Not specified by scanner
Confidence
97% confidence
Finding

The Wrike manifest says the skill is for Wrike operations and explicitly states that trigger-reference files for other sources are platform reference text that add no Wrike capability. This file is a full Linear event-source reference with event types, parameters, and payloads, which describes non-Wrike automation behavior under the Wrike skill package and therefore does not match the skill's claimed functional scope.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The skill's purpose is Wrike project/work management, but this file instructs on consuming Linear webhook events containing names, emails, profile URLs, issue descriptions, and comments. That is a separate third-party event-ingestion capability unrelated to ordinary Wrike API use, and the manifest says Wrike is not an event source and that these shared trigger references add no Wrike capability.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.