Back to skill

Security audit

Gift Genius

Security checks for vulnerabilities and agentic risk

Overview

This gift-shopping skill is not malicious, but it needs review because it expands beyond its stated scope and encourages calendar access and checkout-link creation without clear consent boundaries.

Review before installing. The skill is a shopping assistant that uses AirShelf and merchant checkout links, so it may send gift preferences, recipient context, budget, and location to an external service. Only use it if you are comfortable with the expanded merchant/category scope, and require explicit confirmation before checkout-link generation or any calendar access.

Vulnerability Patterns
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (1)

T05 · Unauthorized Access and Privilege Escalation

Warning
Location
SKILL.md:584
Finding

Proactive Calendar Access Without Explicit User Consent

Content
View full analysis

Vulnerability Details

File Location: SKILL.md, lines 584–586
Vulnerability Type: Unauthorized cross-skill access to private calendar data
Risk Level: Medium

Complete Code Snippet:

markdown
**With Calendar skills:**
- Check if user has "Valentine's Day" event
- Offer proactive: "I see Valentine's is coming up..."

Technical Analysis

The skill instructs the agent to inspect the user's calendar proactively. Calendar access is not necessary for the skill's declared purpose of responding to gift-recommendation requests. The instruction does not require explicit, informed consent before invoking a calendar integration, nor does it define a narrowly scoped query or prohibit access to unrelated event details.

This violates least-privilege principles by encouraging access to a separate source of potentially sensitive personal information beyond what is required to recommend gifts. The resulting proactive statement may also reveal that private calendar data was inspected without the user requesting that action.

Attack Path

  1. The user activates the Gift Genius skill for a gift-related request.
  2. The agent follows the multi-skill integration instructions.
  3. The agent invokes an available calendar tool without first requesting explicit permission.
  4. The calendar integration searches for a Valentine's Day event and may process event metadata returned by the tool.
  5. The agent uses the result to initiate an unsolicited prompt such as, “I see Valentine's is coming up.”
  6. If the calendar tool is broadly scoped, unrelated event information may also become accessible within the agent's execution context.

Impact Assessment

The instruction could cause unauthorized access to private calendar information, including event existence and potentially associated metadata such as dates, attendees, locations, descriptions, or relationship-related context, depending on the calendar tool's permissions ...[truncated 363 chars]

Remediation
View remediation

Remediation Suggestions

  1. Remove the instruction to inspect calendar data proactively.
  2. Require explicit, informed user consent before invoking any calendar integration.
  3. Explain what information will be queried and why before requesting permission.
  4. Limit calendar queries to the narrowest possible scope, such as checking only a user-specified date or event.
  5. Do not retrieve event descriptions, attendees, locations, or unrelated events unless the user explicitly requests them.
  6. Handle denial or unavailable calendar access by continuing with ordinary gift recommendations rather than degrading functionality.
  7. Replace the affected section with consent-based guidance, for example:
    markdown
    **With Calendar skills:**
    - Only access calendar data when the user explicitly asks for calendar-aware assistance.
    - Obtain confirmation before invoking the calendar tool.
    - Query only the date or event explicitly identified by the user.
    
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
Findings (7)

Description-Behavior Mismatch

High
Category
Not specified by scanner
Confidence
98% confidence
Finding

The skill manifest and top-level description promise a narrowly scoped Valentine gift finder for US flowers and Singapore supplements, but the body of the skill silently expands behavior to multiple countries, merchants, and product categories. This scope drift is dangerous because routing and trust decisions may be made from the manifest, while the runtime instructions push the agent into materially different commerce flows the user and platform may not expect.

Content

No source excerpt is available for this finding.

Intent-Code Divergence

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The file gives conflicting instructions about Singapore routing: the header says Singapore users should go to Avea Life supplements, while later sections route them to Far East Flora flowers. Conflicting merchant-routing logic can misdirect users, undermine informed consent, and cause the agent to recommend or purchase from a different merchant/category than the user was led to expect.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

The activation phrases are broad enough to match generic gift-shopping requests, not just Valentine's-focused interactions. Over-broad triggering can cause the skill to activate in unrelated contexts and steer users into this skill's preferred merchants or purchase flow without sufficient relevance.

Content

No source excerpt is available for this finding.

External Transmission

Medium
Category
Data Exfiltration
Confidence
78% confidence
Finding

The skill performs external API requests to a third-party service and may transmit user-derived query content such as recipient type, budget, location, and gift preferences. While external requests are necessary for product search, transmitting potentially sensitive shopping intent without minimization or disclosure creates privacy and data-handling risk.

Content

Scanner excerpt · SKILL.md (reported line 64)May include surrounding context.

Basic search:

bash
curl -s "https://dashboard.airshelf.ai/api/search?q=QUERY&merchant_ids=MERCHANT_ID&min_price=MIN&max_price=MAX&limit=5"

Examples:

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The skill instructs the agent to 'start checkout' and generate one-click checkout links without a strong confirmation boundary or warning that this may initiate a purchase flow. In a commerce setting, this can nudge users into transaction initiation unexpectedly and weakens consent around purchase-adjacent actions.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
90% confidence
Finding

The skill proposes using calendar data to proactively prompt users about Valentine's Day without explaining the privacy implications or requiring consent for calendar access. This can normalize covert use of sensitive personal context and lead to privacy-invasive outreach users did not expect.

Content

No source excerpt is available for this finding.

Vague Triggers

Low
Category
Not specified by scanner
Confidence
89% confidence
Finding

The listed triggers "help me decide" and "which one" are common conversational phrases that can appear in many contexts unrelated to this skill. Because no contextual constraints are stated, these examples risk unintended invocation.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.