Back to skill

Security audit

federal-immigration-expert

Security checks for vulnerabilities and agentic risk

Overview

This skill does useful immigration scoring, but its live-official-policy claims do not match the offline and broader-source behavior in the artifacts.

Install only if you treat it as an offline estimate and monitoring aid, not as live IRCC or legal advice. Verify eligibility, CRS, draws, and program rules directly with IRCC before acting, and review or disable auto_discover/cron behavior if you only want federal canada.ca sources and no scheduled network access.

Vulnerability Patterns
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (8)

Tp4

High
Category
MCP Tool Poisoning
Confidence
89% confidence
Finding
The skill claims federal IRCC-only, live-official, never-stale judgments, but the documented behavior includes broader source discovery, offline snapshots, and approximate scoring. This can mislead users into trusting inaccurate eligibility or policy conclusions, which is dangerous in an immigration decision-support context where users may act on false assurances or omissions.

Intent-Code Divergence

Medium
Confidence
95% confidence
Finding
The README makes materially inconsistent trust and security claims: it says the skill is 'fully local, offline' and requires 'no network', while also asserting that policy judgments come from 'real-time official sources' and describing network-dependent monitoring and source discovery. This can mislead users into granting trust under false assumptions, especially in a policy/compliance skill where users may rely on freshness, privacy boundaries, and execution behavior when deciding whether to install or run it.

Description-Behavior Mismatch

Medium
Confidence
93% confidence
Finding
The manifest promises that policy judgments never rely on stale offline data, yet the skill documentation explicitly uses offline snapshots as fallback. In a regulated domain, this integrity mismatch can cause users to receive outdated legal/policy guidance while believing it is real-time official information.

Intent-Code Divergence

Medium
Confidence
92% confidence
Finding
The documentation contains contradictory instructions about relying exclusively on real-time official sources while also using offline snapshots for fallback and evaluation. Such contradictions undermine trust boundaries and can lead downstream agents or users to over-trust stale content as if it were current law or policy.

Description-Behavior Mismatch

High
Confidence
97% confidence
Finding
The skill claims to provide Canadian federal immigration policy from official sources, but the discovery list includes Ontario provincial pages and a municipal/community website (investsudbury.ca). This can silently expand the trust boundary and cause the agent to ingest non-federal or non-authoritative guidance, leading to incorrect eligibility or policy judgments presented as official federal advice.

Intent-Code Divergence

Medium
Confidence
90% confidence
Finding
The module documentation says it harvests official policy sources, but the code permits a non-government municipal/community site as an allowed source. That mismatch is dangerous because operators and downstream users may trust the dataset as purely official, when it actually contains lower-authority content that can shape answers or updates.

Description-Behavior Mismatch

High
Confidence
98% confidence
Finding
The skill metadata and module docstring claim real-time official policy fetching and update detection, but the implementation is fully offline and relies on hardcoded scoring logic. In an immigration-advice context, this can mislead users into trusting stale or incomplete eligibility decisions as current official guidance, which can materially affect legal/administrative decisions.

Intent-Code Divergence

Medium
Confidence
94% confidence
Finding
The code states that eligibility is based on official local snapshot files, but it never reads those files and instead uses embedded tables and assumptions. This creates a provenance/integrity gap where users or downstream agents may believe results are traceable to official snapshots when they are not.

Static analysis

No suspicious patterns detected.