Back to skill

Security audit

skylight-mcp

Security checks for vulnerabilities and agentic risk

Overview

This skill is a disclosed Skylight account connector with broad but purpose-aligned read/write powers and confirmation gates for the highest-impact actions.

Install only if you want an agent to operate your real Skylight family hub. Use a project-scoped MCP config where possible, keep the credential file private, review prompts carefully before confirming access changes, uploads, bulk deletes, or recurrence-wide edits, and avoid placing sensitive files in the configured upload directories unless you intend to use them with Skylight.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
Findings (7)

MCP Config Access

High
Category
Agent Snooping
Confidence
95% confidence
Finding

The setup instructs users to place credentials in project or global MCP configuration, including a global ~/.claude/mcp.json, which is a sensitive configuration surface. In a skill that authenticates with email/password and can perform extensive family/account actions, normalizing use of globally stored secrets raises the blast radius of local compromise or accidental leakage through logs, backups, or over-broad file access by other tools.

Content

Scanner excerpt · SKILL.md (reported line 15)May include surrounding context.

Setup

Skylight authenticates with your account email + password (OAuth2 authorization-code flow under the hood — no browser extension or API key needed). Add an env block to .mcp.json (project) or ~/.claude/mcp.json (global):

json
{

Description-Behavior Mismatch

High
Category
Not specified by scanner
Confidence
96% confidence
Finding

The manifest omits account/member access-management operations that can invite, approve, remove users, delete member records, and make a frame public. These are high-sensitivity administrative actions; if hidden from the manifest, an orchestrating agent or user may not realize the skill can alter who has access to family data, which materially increases the risk of unauthorized sharing or revocation.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

Medium
Category
Not specified by scanner
Confidence
98% confidence
Finding

The manifest description frames the skill mainly around calendar, chores, lists, and meals, but the body reveals materially broader capabilities including messages, photo albums, uploads, AI auto-creation, and frame/device/member settings. Understating scope can cause users or calling agents to invoke the skill without understanding that it can touch additional sensitive family/account data and perform broader actions than expected.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
97% confidence
Finding

The trigger description includes a broad catch-all condition covering essentially any request involving the Skylight frame, family calendar, chores, rewards, shared lists, or meals. Overly broad activation increases the chance the skill is invoked in ambiguous contexts, causing unintended reads or writes against a real family account when the user did not specifically request this connector.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

The description advertises broad data-changing and account-affecting capabilities without an upfront warning that operations apply to the user's real Skylight family/account. In this context, the skill can modify calendars, chores, lists, meals, media, settings, and access controls, so lack of a prominent warning can mislead users or upstream agents about the consequences of invocation.

Content

No source excerpt is available for this finding.

Autonomous Decision Making

Medium
Category
Excessive Agency
Confidence
80% confidence
Finding

Skill enables autonomous high-impact decisions without human-in-the-loop verification. Critical operations (destructive commands, financial transactions, data deletion) should require explicit user confirmation.

Content

Scanner excerpt · SKILL.md (reported line 38)May include surrounding context.

md
- `SKYLIGHT_FRAME_ID` — pick a frame when your account has more than one (see `skylight_list_frames`). Otherwise the single frame is auto-discovered.
- `SKYLIGHT_NAME` — friendly label shown in diagnostics (defaults to your email).
- `SKYLIGHT_APPLE_APP_PASSWORD` — an app-specific password from appleid.apple.com, used only by `skylight_link_apple_calendar`. It is read from the environment and is **not** a tool argument: never ask the user to paste it into chat.
- `SKYLIGHT_APPLE_ID` — the Apple ID email for that link; the tool's `email` argument overrides it.

Requires a Skylight **email + password** login — Google/Apple/SSO-only accounts aren't supported.

Description-Behavior Mismatch

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The manifest does not disclose that the skill can upload/import local files, including photos and event imports, and set member avatars. Local file interaction is a meaningful expansion of trust because it can expose personal media or import unintended content from the user's machine, especially in a family-hub context.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.