Back to skill

Security audit

tempo-api-mcp

Security checks across malware telemetry and agentic risk

Overview

This Tempo connector matches its time-tracking purpose, but it underplays its ability to read or change team and colleague records and exposes high-impact delete and approval actions without enough safeguards.

Review this carefully before installing in a work Tempo/Jira environment. Use a least-privilege token, confirm your employer allows this automation, avoid exposing reviewer/admin tokens unless needed, and require explicit confirmation before any delete, approval, rejection, reopen, or cross-user/team operation.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
Findings (3)

Intent-Code Divergence

High
Confidence
98% confidence
Finding
The terms section makes a materially false safety claim: it says the server cannot access anyone else's worklogs or colleagues' time entries, but the documented tools support querying team worklogs, fetching other users' worklogs, reviewing approvals, and approving/rejecting timesheets for others. This can mislead users and reviewers about the connector's real authority, increasing the chance of unauthorized access, policy violations, or unsafe deployment in shared/corporate environments.

Vague Triggers

Medium
Confidence
82% confidence
Finding
The trigger description is broad enough that the skill may be invoked for loosely related Jira/Tempo queries without strong intent matching. In a skill that can create, update, delete, submit, approve, reject, and reopen records, accidental invocation increases the chance of unnecessary data exposure or unintended state-changing actions.

Missing User Warnings

Medium
Confidence
90% confidence
Finding
The markdown lists destructive operations such as deleting worklogs, plans, teams, and accounts without prominent safety guidance at the point of introduction. Although timesheet actions later mention confirm-gating, the deletion capabilities are exposed in the tool list with no adjacent warning, which raises the risk of accidental destructive use by an agent or user.

VirusTotal

VirusTotal findings are pending for this skill version.

View on VirusTotal

Static analysis

No suspicious patterns detected.