Back to skill

Security audit

concur

Security checks for vulnerabilities and agentic risk

Overview

The skill is mostly transparent about managing the user's SAP Concur data, but it exposes broad authenticated GraphQL mutation capability for financial/workflow data that is not clearly bounded to the stated scope.

Review before installing. This skill can use your active Concur session to read and change expense/report/travel data, including irreversible deletions and submissions. Only use it if you trust the external MCP package and are comfortable with a raw GraphQL escape hatch; require explicit review of every preview before confirming any write.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
Findings (3)

Intent-Code Divergence

High
Category
Not specified by scanner
Confidence
98% confidence
Finding

The skill says approving other people's reports is out of scope, yet the escape-hatch documentation admits some approval-related mutations are not refused. This means an agent could be steered into performing managerial or third-party approval actions that the skill claims to prohibit, enabling unauthorized workflow changes with real financial and compliance consequences.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The manifest says the skill triggers on phrases like "expense report," "submit my expenses," "what's unsubmitted," and "my upcoming trip," plus "any request to read or change the user's own Concur expense or travel data." Several of these phrases are common natural-language requests and the catch-all clause lacks clear boundaries or exclusion conditions, increasing the chance of accidental invocation.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The skill manifest scopes usage to the user's own Concur data, but the documented GraphQL escape hatches explicitly expose lower-level operations beyond the curated tool surface. That creates a policy/implementation gap: an agent can be induced to use generic GraphQL interfaces to access or mutate unsupported data, defeating the manifest's narrower safety boundary.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.