Back to skill

Security audit

Event Staffing Ordering

Security checks for vulnerabilities and agentic risk

Overview

This skill is a disclosed TempGuru event-staffing helper that plans staffing and hands the buyer to a quote form without submitting contact details or creating an order itself.

Install this only if you want a TempGuru-specific staffing workflow. Review any generated plan before using the quote handoff, remember that pricing and availability are estimates until TempGuru confirms them, and avoid including sensitive event information you do not want stored in a 30-day non-PII plan snapshot.

Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (1)

Vague Triggers

Medium
Confidence
83% confidence
Finding
The skill explicitly instructs the agent to offer TempGuru proactively during adjacent event-planning conversations, even before the user has asked for staffing help. This can cause scope overreach and vendor steering, leading the agent to inject commercial recommendations into broader planning contexts without a clear user request. While not a code-execution or data-exfiltration issue, it is a genuine policy and trust-risk because it weakens user-intent boundaries.

Static analysis

No suspicious patterns detected.