Back to skill

Security audit

angi-mcp

Security checks for vulnerabilities and agentic risk

Overview

This skill is a disclosed, read-only Angi data helper, but users should be careful because it relies on a browser-paired fetch tool that can use the active Angi session when explicitly paired.

Install only if you trust @fetchproxy/cli and the ContextMint Bridge extension. Pair only www.angi.com for public directory lookups, and do not pair my.angi.com unless you intentionally want the agent to read your signed-in Angi account pages. Treat extracted review/profile output as potentially personal data and follow Angi's terms.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Vulnerability Patterns
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
Findings (7)

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 79)May include surrounding context.

md
| node references/rsc.mjs legacyId --dedupe id \

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 83)May include surrounding context.

md
| node references/rsc.mjs legacyId --dedupe id \

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 98)May include surrounding context.

md
| node references/rsc.mjs legacyId --dedupe id \

Description-Behavior Mismatch

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

The skill’s declared purpose is public Angi directory lookup, but it also includes explicit instructions to access authenticated data on my.angi.com via the user’s existing browser session. That expands the skill from public scraping into session-bound account data access, creating a risk of unnecessary exposure of personal account information and privilege creep beyond the stated use case.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

The skill includes capability to read authenticated account pages and JSON endpoints even though its stated purpose is finding pros, ratings, reviews, and taxonomy data. This mismatch is dangerous because users or higher-level agents may invoke the skill expecting only public directory access, while the implementation can silently leverage an authenticated browser tab to retrieve private user data.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
88% confidence
Finding

The file instructs users to fetch and extract review records and provider details, including fields like userName, address components, comments, and business identifiers, but does not include any warning about handling personal data or respecting site terms. Under the markdown-file criteria, this is a missing warning for behavior that could affect privacy or user data handling.

Content

No source excerpt is available for this finding.

Intent-Code Divergence

Low
Category
Not specified by scanner
Confidence
71% confidence
Finding

The note frames the capability boundary as primarily public data plus the user's own account data, but elsewhere the skill relies on browser-tab session context and Cloudflare-cleared browsing state to fetch content. This is not a direct contradiction for the directory pages, but the wording understates that the skill's effective access is whatever the paired browser session can read on the covered hosts, including authenticated surfaces.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.