Back to skill

Security audit

Daily Sleep

Security checks for vulnerabilities and agentic risk

Overview

This appears to be a disclosed sleep-coaching skill that schedules opt-in morning and evening reminders and stores only simple per-user reminder preferences.

Install only if you want recurring sleep reminders. Use the provided off command to disable them, avoid putting sensitive information in the userId, and consider narrowing trigger phrases if accidental activation would be disruptive.

Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
Findings (4)

Tp4

High
Category
MCP Tool Poisoning
Confidence
95% confidence
Finding
The skill description promises an evening sleep aid, but the documented behavior includes morning pushes, persistent user configuration, and multi-channel delivery controls that materially expand data handling and notification capabilities. This mismatch can undermine informed user consent and platform review, especially because scheduling and storing per-user push settings introduces privacy and abuse considerations not disclosed in the description.

Vague Triggers

Medium
Confidence
86% confidence
Finding
The trigger list includes broad generic phrases such as "sleep," "can't sleep," and related common-language terms without scope limits, which can cause the skill to activate in unintended contexts. In a health-adjacent skill, overbroad triggering is risky because it may inject unsolicited wellness guidance into unrelated conversations or sensitive situations, increasing misrouting and user trust issues.

Vague Triggers

Medium
Confidence
83% confidence
Finding
The trigger phrases are broad and generic, which can cause the skill to activate when the user is merely discussing sleep problems rather than requesting this specific skill. Unintended invocation can lead to surprise notifications, collection or use of preferences, or confusing behavior in unrelated conversations.

Vague Triggers

Medium
Confidence
89% confidence
Finding
The package description explicitly advertises a 'Daily evening push,' which implies recurring proactive engagement without stating any clear user-controlled activation constraints, consent flow, or rate limits. In an agent skill, broad recurring-trigger language can enable unwanted notifications or repeated contact patterns, creating privacy, spam, and user-trust risks even if the functionality is framed as wellness-focused.

Static analysis

No suspicious patterns detected.