Back to skill

Security audit

Luma Events Enhanced

Security checks for vulnerabilities and agentic risk

Overview

The skill fetches public Luma event listings and stores a disclosed local event cache, with no evidence of credential theft, code execution, or deceptive behavior.

Install only if you are comfortable with the skill contacting lu.ma and saving fetched public event metadata locally for follow-up questions. Treat event names, venues, and host text as untrusted external content, and clear the memory file if you do not want prior event lookups retained.

Vulnerability Patterns
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Findings (1)

T02 · Agent Memory Poisoning

Warning
Location
scripts/fetch_events.py:202
Finding

Untrusted Remote Event Content Persisted in Agent Memory

Content
View full analysis
Remediation
View remediation
Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Taint TrackingDirect Taint Flow, Variable-Mediated Taint Flow, Credential Exfiltration Chain
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
Findings (8)

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 118)May include surrounding context.

md
- Removed obsolete `README.md`; consolidated docs in `SKILL.md`.

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
92% confidence
Finding

The skill advertises and relies on network access plus local file read/write persistence, but it does not declare any explicit tool scope or permissions boundaries. That increases the chance the agent invokes the skill with broader capabilities than the user expects, weakening least-privilege controls and making unintended data access or persistence harder to audit.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

The invocation description is broad enough to match many generic requests about events, meetups, conferences, and things happening in cities, which can cause over-triggering. In an agent environment, an over-broad trigger can silently expand network activity and local persistence into conversations where the user did not specifically ask to use Luma or fetch/store external event data.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The skill auto-persists fetched event data to a local memory file, but this retention behavior is not clearly surfaced in the high-level description where a user or orchestrator would expect privacy-relevant behavior to be disclosed. Hidden or under-disclosed persistence can create privacy and compliance issues, especially if queries, venues, hosts, or user-interest patterns are later inferred from stored event data.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The skill silently persists fetched event data to a workspace memory file even though its declared purpose is just to fetch and return upcoming events. Hidden statefulness increases data-retention risk, creates side effects across runs, and can surprise operators who expect a read-only lookup tool.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

This code manages local event history by loading, overwriting, and pruning records on disk, adding undisclosed stateful behavior. Such persistence can accumulate external content across sessions and expose prior query history or fetched metadata to other components that can access the workspace.

Content

No source excerpt is available for this finding.

Tainted flow: 'EVENTS_FILE' from os.getenv (line 19, credential/environment) → open (file write)

Medium
Category
Data Flow
Confidence
65% confidence
Finding

Data from a source is assigned to a variable that is later passed to a sink, creating a variable-mediated taint flow.

Content

Scanner excerpt · scripts/fetch_events.py (reported line 38)May include surrounding context.

python
def save_events(events):
    """Save events to JSON file, overwriting."""
    ensure_memory_dir()
    with open(EVENTS_FILE, 'w', encoding='utf-8') as f:
        json.dump(events, f, indent=2, ensure_ascii=False)

def prune_old_events(events, hours=24):

Description-Behavior Mismatch

Medium
Category
Not specified by scanner
Confidence
97% confidence
Finding

During standard execution, the skill updates and saves event history as a side effect of answering requests, rather than only returning fetched results. In an agent environment, this is more dangerous because workspace memory may be shared or later consumed by other skills, enabling unintended cross-session data exposure and behavior not described to users.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.