Back to skill

Security audit

Sentiet ORB

Security checks for vulnerabilities and agentic risk

Overview

This skill needs Review because it silently combines private messages, calendar data, Downloads metadata, and logged-in social accounts to generate daily predictions with broad permissions and limited user control.

Review carefully before installing. Do not grant Full Disk Access or browser-cookie access unless you accept that the agent can read private messages, calendar details, Downloads metadata, and authenticated social pages. Prefer disabling the cron job, using an isolated browser profile, requiring per-run approval, and confirming the model is truly local before allowing this skill to run.

Vulnerability Patterns
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
Findings (2)

T05 · Unauthorized Access and Privilege Escalation

Error
Location
SKILL.md:11
Finding

Excessive Access to Sensitive Personal Data and Authentication Sessions

Content
View full analysis
datetime('now', '-24 hours') ORDER BY date DESC LIMIT 50; ``` #### D. System Signals - **Action**: Check `~/Downloads` for recent files. ```bash find ~/Downloads -type f -mtime -1 -print ``` ``` The README additionally requests broad operating-system access: ```markdown - **Permissions**: The agent requires: - **Full Disk Access**: To read `~/Library/Messages/chat.db`. - **Calendar Access**: To query local events. ``` ### Technical Analysis The skill aggregates several highly sensitive data classes in one agent context: - Authenticated Instagram and Twitter sessions through existing browser cookies - Private iMessage content from `chat.db` - Calendar events and associated personal or professional cont ...[truncated 2146 chars]
Remediation
View remediation

T08 · Insecure Dependencies

Warning
Location
README.md:31
Finding

Unpinned and Inconsistent Skill Installation Source

Content
View full analysis
Remediation
View remediation
Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
Findings (10)

Missing User Warnings

High
Category
Not specified by scanner
Confidence
93% confidence
Finding

The README instructs users to grant Full Disk Access and browser cookie access, both of which are highly sensitive permissions that can expose messages, authentication material, and other unrelated personal data. Presenting these steps as routine troubleshooting without a strong security warning normalizes dangerous over-privileging and materially increases the blast radius if the skill is misused or compromised.

Content

No source excerpt is available for this finding.

Intent-Code Divergence

High
Category
Not specified by scanner
Confidence
99% confidence
Finding

The skill declares a "local-only" safety policy while explicitly instructing the agent to access Instagram and Twitter via browser automation and existing cookies. This mismatch is dangerous because it can mislead users and reviewers about the true trust boundary, while the skill still performs external service interaction using sensitive authenticated sessions.

Content

No source excerpt is available for this finding.

Missing User Warnings

High
Category
Not specified by scanner
Confidence
98% confidence
Finding

The skill is designed as a silent background process that reads calendar entries, browser cookies, iMessage data, and recent downloads, yet it does not provide a meaningful warning about the breadth and sensitivity of this collection at runtime. That creates a covert monitoring pattern where highly personal data is processed without clear, contemporaneous user awareness or consent.

Content

No source excerpt is available for this finding.

Ssd 4

High
Category
Not specified by scanner
Confidence
99% confidence
Finding

The workflow is explicitly stealth-oriented: it adds anti-ban jitter, performs headless scraping with existing cookies, mines private messages and files, and emits only a polished personalized result while hiding the underlying surveillance. In this context, the combination of covert collection, evasion language, and source concealment strongly increases danger because it operationalizes hidden monitoring rather than transparent assistance.

Content

No source excerpt is available for this finding.

Ssd 3

High
Category
Not specified by scanner
Confidence
99% confidence
Finding

These instructions direct the agent to gather sensitive communications and social data, correlate them with named individuals, and then conceal the true sources in the final output. That is dangerous because it turns private data into untransparent behavioral inferences, undermining user autonomy and enabling covert profiling or manipulation.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The skill is described as silently reading highly sensitive local sources such as iMessage and calendar data, but the README does not prominently warn users about the privacy implications of this access. In the context of an automated background task, this increases the risk that users enable broad surveillance-like behavior without informed consent.

Content

No source excerpt is available for this finding.

Intent-Code Divergence

Medium
Category
Not specified by scanner
Confidence
88% confidence
Finding

The documentation claims that all processing is local and no personal data is sent to the cloud, yet it also states that sensitive message and calendar data are injected into an LLM context. If the model is remote or configurable, this claim is misleading and may cause users to expose personal data under a false privacy assurance.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

Medium
Category
Not specified by scanner
Confidence
84% confidence
Finding

The README introduces social scraping and anti-detection behavior that goes beyond the stated purpose of generating a local 'daily oracle' from personal context. Expanding collection to public social data and using execution jitter to avoid detection increases the chance of unauthorized collection, policy evasion, and privacy overreach without clear necessity or consent framing.

Content

No source excerpt is available for this finding.

Intent-Code Divergence

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The privacy notice narrowly says data is not sent to third-party logging services, but the documented workflow still transmits session-backed requests and behavioral data to third-party social platforms during scraping. Even if content is processed locally, contacting those platforms can expose account activity, metadata, and surveillance-derived targets, making the notice materially misleading.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The skill pushes notifications containing personal predictions and inferred relationship/context signals to the device surface, where lock-screen previews or bystanders may see them. Because the notification can reveal sensitive conclusions derived from messages, calendar items, and social activity, it risks unintended disclosure beyond the user.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.