Back to skill

Security audit

Event Staffing Procurement

Security checks for vulnerabilities and agentic risk

Overview

This skill connects to TempGuru’s disclosed staffing-policy and planning MCP, with user-confirmed quote handoff and no hidden executable or persistence behavior found.

Before installing, users should be comfortable with the skill calling TempGuru’s external MCP for policy, city, role, pricing, compliance, and plan-handoff data. Do not enter personal contact details into the agent; the skill says those should be entered only on the TempGuru-owned form after the buyer chooses to proceed.

Vulnerability Patterns
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (1)

Description-Behavior Mismatch

Medium
Confidence
83% confidence
Finding
The skill is presented as narrowly focused on procurement-policy questions, but it is connected to a much broader MCP that exposes planning, pricing, compliance, and quote operations. That mismatch increases the risk of over-broad tool access, allowing the agent to invoke capabilities outside the user-expected scope and potentially disclose sensitive business data or trigger operational actions such as quote-related workflows.

Static analysis

No suspicious patterns detected.