Back to skill

Security audit

jobber-mcp

Security checks for vulnerabilities and agentic risk

Overview

This skill is a disclosed, read-only helper for fetching and parsing a user's own Jobber Client Hub data through an approved browser bridge.

Install only if you are comfortable granting the fpx bridge read access to your signed-in Jobber tab. Treat the hub URL and any saved HTML or JSON output like private billing data, verify the CLI and extension sources, and keep the extension site access limited to getjobber.com.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (8)

Anti-Refusal Statement

High
Category
Anti-Refusal
Confidence
80% confidence
Finding

Skill instructs the agent to omit warnings, disclaimers, or ethical commentary. Stripping safety caveats hides risk from the user and is a common jailbreak preamble.

Content

Scanner excerpt · SKILL.md (reported line 106)May include surrounding context.

md
looks like "you have no invoices" rather than like a bug.

The parser warns on stderr whenever it returns an empty list, for exactly this
reason. An empty result with no warning means the page genuinely had none.

## Exit codes

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
88% confidence
Finding

The skill instructs the user to perform live network access via the external fpx CLI and a browser extension, but it does not declare explicit tool scope or permissions metadata. In an agent setting, missing scope declarations can cause network-capable behavior to be invoked without clear policy boundaries, increasing the risk of unintended data access to sensitive customer portal content.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

Line L140 redirects a fetched invoice detail page into invoice.html, which creates a local copy of potentially sensitive billing and customer information. The surrounding text explains how to do this but does not include any warning about local data retention, sensitivity, or cleanup.

Content

No source excerpt is available for this finding.

External Transmission

Medium
Category
Data Exfiltration
Confidence
60% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · references/why-not-the-api.md (reported line 29)May include surrounding context.

sh
# unauthenticated: the field is hidden, not rejected
curl -s -X POST https://api.getjobber.com/api/graphql \
  -H 'Content-Type: application/json' \
  -H 'X-JOBBER-GRAPHQL-VERSION: 2025-04-16' \
  -d '{"query":"{ account { id name } }"}'

External Transmission

Medium
Category
Data Exfiltration
Confidence
50% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · references/why-not-the-api.md (reported line 29)May include surrounding context.

sh
# unauthenticated: the field is hidden, not rejected
curl -s -X POST https://api.getjobber.com/api/graphql \
  -H 'Content-Type: application/json' \
  -H 'X-JOBBER-GRAPHQL-VERSION: 2025-04-16' \
  -d '{"query":"{ account { id name } }"}'

External Transmission

Medium
Category
Data Exfiltration
Confidence
50% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · references/why-not-the-api.md (reported line 37)May include surrounding context.

sh
# unauthenticated: the field is hidden, not rejected
curl -s -X POST https://api.getjobber.com/api/graphql \
  -H 'Content-Type: application/json' \
  -H 'X-JOBBER-GRAPHQL-VERSION: 2025-04-16' \
  -d '{"query":"{ account { id name } }"}'

External Transmission

Medium
Category
Data Exfiltration
Confidence
50% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · references/why-not-the-api.md (reported line 42)May include surrounding context.

sh
# unauthenticated: the field is hidden, not rejected
curl -s -X POST https://api.getjobber.com/api/graphql \
  -H 'Content-Type: application/json' \
  -H 'X-JOBBER-GRAPHQL-VERSION: 2025-04-16' \
  -d '{"query":"{ account { id name } }"}'

External Transmission

Medium
Category
Data Exfiltration
Confidence
50% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · references/why-not-the-api.md (reported line 77)May include surrounding context.

sh
# unauthenticated: the field is hidden, not rejected
curl -s -X POST https://api.getjobber.com/api/graphql \
  -H 'Content-Type: application/json' \
  -H 'X-JOBBER-GRAPHQL-VERSION: 2025-04-16' \
  -d '{"query":"{ account { id name } }"}'

Static analysis

No suspicious patterns detected.