Back to skill

Security audit

Pndr

Security checks for vulnerabilities and agentic risk

Overview

This skill is a legitimate Pndr MCP integration, but it asks users to store a long-lived account token for broad read/write/delete access without enough safety guidance.

Install only if you are comfortable giving your AI assistant access to private Pndr data and, on Pro accounts, the ability to create, modify, complete, archive, and delete records. Treat the client secret and bearer token like passwords: do not share them, commit config files, or include them in logs/screenshots, and rotate or revoke credentials if exposed. Consider using read-only access where possible and confirm destructive requests before allowing them.

Vulnerability Patterns
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (1)

T09 · Insecure Skill Coding Practices

Warning
Location
SKILL.md:84
Finding

Long-Lived Bearer Token Stored in Plaintext Configuration

Content
View full analysis

Vulnerability Details

File Location: SKILL.md:84-108 and SKILL.md:245-247
Vulnerability Type: Plaintext storage of a long-lived bearer token
Risk Level: Medium

Vulnerable Code

json
{
  "mcpServers": {
    "pndr": {
      "baseUrl": "https://pndr.io/mcp",
      "headers": {
        "Authorization": "Bearer YOUR_ACCESS_TOKEN"
      }
    }
  }
}
json
{
  "mcpServers": {
    "pndr": {
      "url": "https://pndr.io/mcp",
      "headers": {
        "Authorization": "Bearer YOUR_ACCESS_TOKEN"
      }
    }
  }
}
text
Pndr uses OAuth 2.0 client credentials flow. Access tokens expire after 1 year (365 days).

To refresh your token, repeat the `curl` command from step 2 and update your mcporter config with the new Bearer token.

Technical Analysis

The documented configuration embeds a bearer access token directly in the mcporter or Claude Desktop configuration file. Bearer tokens grant access based solely on possession, so any process or user capable of reading the configuration can reuse the token without knowing the OAuth client secret.

The documented one-year validity period substantially extends the period during which a copied token may be abused. Configuration files may also be exposed through overly broad file permissions, source-control commits, workstation backups, diagnostic archives, support bundles, malware, or other local processes.

The file contains placeholders rather than an actual secret, so no credential is directly disclosed by the audited project. The vulnerability is in the recommended credential-storage practice and prolonged token lifetime.

Attack Path

  1. A user follows the instructions and places a real Pndr bearer token directly in an MCP configuration file.
  2. An attacker obtains read access to that file through local account compromise, weak file permissions, a leaked backup, an accidental repository commi ...[truncated 1080 chars]
Remediation
View remediation

Remediation Suggestions

  1. Avoid embedding bearer tokens directly in ordinary JSON configuration files. Support environment-variable interpolation or references to an external credential provider.
  2. Store credentials in an operating-system secret facility such as macOS Keychain, Windows Credential Manager, Linux Secret Service, or a dedicated secrets manager.
  3. Reduce access-token validity from one year to a short lifetime and use a securely stored refresh token or interactive OAuth authorization when renewal is required.
  4. Provide explicit token revocation and rotation mechanisms, including instructions for immediate revocation after suspected exposure.
  5. Apply least-privilege scopes so read-only use does not receive write or deletion permissions.
  6. Restrict configuration-file permissions to the owning user and warn users not to commit configuration files, include them in support bundles, or store them in unencrypted backups.
  7. Add secret-scanning rules for Pndr token formats and document incident-response steps for leaked credentials.
  8. Where plaintext configuration is unavoidable, clearly disclose the risk and recommend full-disk encryption, restrictive permissions, and regular credential rotation.
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Rogue AgentSelf-Modification, Session Persistence
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
Findings (7)

Credential Access

High
Category
Privilege Escalation
Confidence
90% confidence
Finding

The instructions explicitly tell users to copy a client_id and client_secret, then obtain an access token, but provide no safeguards for handling these credentials. Because these secrets grant API access to personal productivity data and write/delete operations, exposure could allow account compromise or unauthorized data manipulation.

Content

Scanner excerpt · SKILL.md (reported line 70)May include surrounding context.

  • Give it a name (e.g., "My AI Assistant")
    • Copy your client_id and client_secret
  1. Get an access token:
    bash
    curl -X POST https://pndr.io/oauth/token \
      -H "Content-Type: application/json" \
    

Credential Access

High
Category
Privilege Escalation
Confidence
88% confidence
Finding

The authentication section normalizes long-lived access tokens lasting 365 days without emphasizing the security consequences if such a token is leaked. Long token lifetimes significantly extend the window for unauthorized access, especially when the same document also recommends storing bearer tokens in local config.

Content

Scanner excerpt · SKILL.md (reported line 245)May include surrounding context.

md
## Authentication

Pndr uses OAuth 2.0 client credentials flow. Access tokens expire after 1 year (365 days).

To refresh your token, repeat the `curl` command from step 2 and update your mcporter config with the new Bearer token.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The skill advertises that the agent can add, edit, complete, delete, and otherwise modify a user's personal data, but it does not clearly warn that these actions can change or permanently remove account content. In an agent-integrated context, missing disclosure increases the risk of users triggering destructive operations unintentionally through natural-language requests.

Content

No source excerpt is available for this finding.

Session Persistence

Medium
Category
Rogue Agent
Confidence
80% confidence
Finding

Skill establishes unauthorized persistence across sessions via cron jobs, startup scripts, or state files. Session persistence allows an attacker to maintain access beyond the current interaction.

Content

Scanner excerpt · SKILL.md (reported line 30)May include surrounding context.

md
Pndr exposes your personal productivity data through the Model Context Protocol (MCP), allowing AI assistants to interact with your tasks, habits, and journal on your behalf.

**Example conversations:**
- "Add a task to call mom tomorrow with high priority"
- "What's on my plate today?"
- "Mark my exercise habit as complete"
- "Show me my accomplishments this week"

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
97% confidence
Finding

The setup instructions direct users to copy client secrets and bearer tokens into commands and configuration files, but they do not warn that these are sensitive credentials that must be protected. This can lead to accidental exposure through shell history, screenshots, committed config files, or shared workstation profiles, enabling unauthorized access to the user's Pndr account.

Content

No source excerpt is available for this finding.

External Transmission

Medium
Category
Data Exfiltration
Confidence
60% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · SKILL.md (reported line 72)May include surrounding context.

  1. Get an access token:
    bash
    curl -X POST https://pndr.io/oauth/token \
      -H "Content-Type: application/json" \
      -d '{
        "grant_type": "client_credentials",
    

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The tool list includes many destructive operations such as delete, archive, and mark-complete actions without an explicit warning that some changes may be irreversible or affect user records. In an MCP/agent setting, exposing broad write/delete capabilities without user-facing caution materially raises the chance of accidental data loss.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.