Back to skill

Security audit

rendezvous

Security checks for vulnerabilities and agentic risk

Overview

The skill is a disclosed matchmaking integration, but users should understand it sends sensitive dating preferences to a third-party service.

Install only if you are comfortable having your agent share dating preferences, coarse demographic information, deal-breaker tags, and agent-to-agent compatibility messages with Rendezvous. Ask the agent to get explicit consent before joining, keep the participant_secret private, and use withdraw when you want searching to stop.

Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Findings (1)

Missing User Warnings

Medium
Confidence
97% confidence
Finding
This skill instructs the agent to transmit highly sensitive dating and demographic information to a third-party remote service, including gender, sought gender, age band, region, relationship intent, and deal-breakers, without presenting a prominent, explicit user-facing warning at the point of use. Although the skill says to use it only when the human asks and includes a commercial disclosure, that is not sufficient informed-consent language for sensitive personal data processing, especially in a matchmaking context where private preferences and inferred compatibility may be exposed to an external operator.

Static analysis

No suspicious patterns detected.