Back to skill

Security audit

Staffing Agency Partner Growth

Security checks for vulnerabilities and agentic risk

Overview

This skill coherently helps staffing agencies contact TempGuru and uses disclosed read-only catalog lookups that fit that purpose.

Before installing, understand that the skill may contact TempGuru's live MCP service to look up markets, roles, and client bill-rate benchmarks, and it may help draft or send an email to the listed TempGuru contact only after confirmation. Do not use it for job applications or buyer staffing quotes.

Vulnerability Patterns
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (1)

Description-Behavior Mismatch

Medium
Confidence
90% confidence
Finding
The manifest says the skill should only assess and route staffing-agency partner inquiries, but it is connected to a live MCP tool that exposes market, role, and rate-benchmark functionality. That creates unnecessary capability expansion: an agent handling simple intake could query operational or commercially sensitive data, increasing the risk of over-collection, misuse, or prompt-driven tool abuse if the conversation is manipulated.

Static analysis

No suspicious patterns detected.