Back to skill

Security audit

Events

Security checks for vulnerabilities and agentic risk

Overview

This skill is a straightforward local event-tracking template, but users should be careful because it stores personal event details in ordinary local files.

Install only if you are comfortable keeping event plans, birthdays, guest lists, and ticket or reservation identifiers in ~/events/ as local Markdown files. Avoid storing unnecessary confirmation numbers or third-party personal details, and consider using a protected folder or restrictive file permissions on shared or synced machines.

Vulnerability Patterns
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (1)

T09 · Insecure Skill Coding Practices

Warning
Location
SKILL.md:93
Finding

Plaintext Storage of Sensitive Event, Ticket, and Attendance Data

Content
View full analysis

Vulnerability Details

File Location: SKILL.md:11, SKILL.md:38-39, and SKILL.md:93-98
Vulnerability Type: Plaintext sensitive-data storage without access-control or retention safeguards
Risk Level: Medium

Vulnerable Code Snippets

SKILL.md:11:

markdown
- Create `~/events/` as workspace

SKILL.md:38-39:

markdown
Section 112, Row 8
Confirmation: TM-789456

SKILL.md:93-98:

markdown
## What To Track
- Date, time, location
- Tickets/confirmation numbers
- Logistics (parking, doors, dress code)
- Who you're going with
- RSVPs when hosting

Technical Analysis

The Skill directs the Agent to create a persistent workspace under the user's home directory and store ticket confirmation numbers, event locations, attendance relationships, and RSVP information in Markdown files. These records may contain security-sensitive ticket identifiers and personal information about the user and third parties.

The instructions do not require owner-only file permissions, encryption, identifier redaction, user consent before retaining third-party information, or a retention and deletion policy. Consequently, the default implementation can leave sensitive records exposed to other locally authorized users or processes, backup software, indexing services, and synchronization tools that can access the workspace.

The example confirmation number is illustrative rather than a real embedded credential. The risk arises from instructing the Agent to place future user-supplied confirmation numbers and personal event data into plaintext storage.

Attack Path

  1. The user activates the Skill and asks the Agent to track an event.
  2. The Agent creates the documented ~/events/ workspace.
  3. The user supplies a ticket confirmation number, appointment information, event location, companion details, or guest RSVP data.
  4. Following the Skill instructions, the Agent writes that info ...[truncated 1271 chars]
Remediation
View remediation

Remediation Suggestions

  1. Store only non-sensitive event summaries by default and require explicit user consent before retaining confirmation numbers, appointment details, or third-party RSVP information.
  2. Redact confirmation identifiers in routine views, retaining only a short suffix when the complete value is unnecessary.
  3. Create the workspace and files with owner-only permissions, such as directory mode 0700 and file mode 0600 on platforms that support POSIX permissions.
  4. Provide an encrypted or operating-system-protected storage option for ticket and reservation credentials instead of ordinary Markdown.
  5. Warn users that the workspace may be included in backups, search indexes, or cloud synchronization, and allow them to choose a protected location.
  6. Define retention controls that archive or delete sensitive ticket and RSVP data after the event.
  7. Minimize third-party personal data, record it only for the stated event-management purpose, and support review and deletion on request.
  8. Ensure logs, generated calendar summaries, and surfaced reminders do not reproduce complete confirmation numbers.
Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (2)

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The activation triggers are very broad ('User mentions event', 'planning event', 'what's coming up'), which can cause the skill to invoke in many ordinary conversations and collect or surface personal scheduling data unexpectedly. In a skill that stores dates, venues, confirmation numbers, birthdays, and RSVP details in local files, unintended activation increases the chance of privacy leakage, accidental persistence of sensitive data, or confusing the user about when data is being recorded.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The skill encourages storing sensitive personal data locally, including confirmation numbers, birthdays, venues, attendance lists, and logistics, but provides no warning about privacy or device security. That omission can lead users to place personally identifiable or security-relevant information in predictable plaintext files, increasing exposure if the machine is shared, compromised, or synced insecurely.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.