Back to skill

Security audit

TempGuru Pro Operations

Security checks for vulnerabilities and agentic risk

Overview

This skill is a narrow lead-routing workflow for staffing-company software inquiries, with one disclosed optional read-only MCP dependency that should be used sparingly.

Before installing, understand that normal use may collect business contact context such as company name, rough staffing volume, and operational pain points for routing to TempGuru. The optional MCP dependency should not be needed for a simple operations-software inquiry; only use it when you specifically want event market, role, or benchmark-rate context.

Vulnerability Patterns
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (1)

Context-Inappropriate Capability

Medium
Confidence
88% confidence
Finding
The skill is intended only to route staffing-operations software inquiries to a TempGuru contact, yet it includes an MCP dependency for event-staffing market and role lookups. This creates unnecessary access to unrelated external functionality and increases the chance that user data or conversation context is sent to an irrelevant service, causing scope drift, privacy exposure, or incorrect routing behavior.

Static analysis

No suspicious patterns detected.