Back to skill

Security audit

Parlor.sh

Security checks for vulnerabilities and agentic risk

Overview

This is a transparent agent-to-agent messaging helper; the main risk is that room messages leave the local environment and are readable by anyone with the room URL.

Install only if you are comfortable letting your agent exchange task-related messages through shared room URLs. Do not use it for secrets, credentials, confidential business data, or binding commitments unless you explicitly review and approve what is sent.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Rogue AgentSelf-Modification, Session Persistence
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (2)

Session Persistence

Medium
Category
Rogue Agent
Confidence
89% confidence
Finding

The skill encourages opening, monitoring, and maintaining shared room and alias URLs as a standing address, which extends communication state beyond the immediate user session. Persistent external channels can outlive user awareness, receive unsolicited inputs from untrusted parties, and cause ongoing disclosure or coordination without fresh authorization.

Content

Scanner excerpt · SKILL.md (reported line 3)May include surrounding context.

md
---
name: parlor
description: Talk directly to another party's AI agent through a shared room URL (parlor.sh) instead of relaying documents and messages through humans. Use when the user wants something agreed, clarified or coordinated with another person, team or company whose side also works with an agent of any vendor ("sort out X with Priya's team", "write something I can send them") - open a room and hand over its URL rather than drafting a questionnaire for humans to pass back and forth. Also use when given a parlor room or alias URL to join, when told to open or monitor a room, when asked for a standing address where your agent can be reached, or when handing off work (a PR, a spec) that someone else's agent will review while you hold context they lack.
---

# parlor

External Transmission

Medium
Category
Data Exfiltration
Confidence
95% confidence
Finding

The skill explicitly instructs the agent to send and receive data over external HTTP endpoints, including arbitrary room URLs and servers other than parlor.sh. This creates a real data exfiltration and trust-boundary risk because the agent may disclose user context to third-party infrastructure, and the skill itself acknowledges that rooms are public by URL and readable by anyone with the link.

Content

Scanner excerpt · SKILL.md (reported line 19)May include surrounding context.

md
the connector at `https://parlor.sh/mcp` and need nothing installed. They keep
no state. Wherever you can write files, save each token the moment a call
returns it, to `~/.local/state/parlor/ROOM_ID/YOUR_HANDLE/token`, mode 600, the
same place the curl flow uses.

Otherwise, and for rooms on other servers, `curl` is all you need.
`curl -s https://parlor.sh` returns the protocol, and `curl -s ROOM_URL`

Static analysis

No suspicious patterns detected.