Back to skill

Security audit

AR VR Developer

Security checks for vulnerabilities and agentic risk

Overview

This skill is a straightforward AR/VR career-roadmap API wrapper, with expected external processing of user-provided assessment data but no hidden code, persistence, or privilege-seeking behavior.

Before installing, understand that career assessment details, goals, session IDs, timestamps, and optional user IDs may be sent to the listed external API service. Avoid including unnecessary personal details if you do not want them processed externally.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (4)

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The skill explicitly describes collecting and transmitting detailed assessment data, session identifiers, timestamps, and optional user identifiers to an external API, but it provides no user-facing privacy notice, consent flow, data handling statement, or minimization guidance. This is risky because career assessment data can be personal profiling data, and the added tracking fields increase the chance of unnecessary retention, linkage, or misuse.

Content

No source excerpt is available for this finding.

External Transmission

Medium
Category
Data Exfiltration
Confidence
72% confidence
Finding

The skill routes data to an external domain, which means user assessment content and tracking metadata leave the local trust boundary. In this context, the danger is amplified because the payload includes skill inventory, career goals, session IDs, timestamps, and optional user IDs, yet the skill does not describe trust validation, data protection expectations, or restrictions on what should be sent.

Content

Scanner excerpt · SKILL.md (reported line 199)May include surrounding context.

md
## References

- **Kong Route:** https://api.mkkpro.com/career/ar-vr-developer
- **API Docs:** https://api.mkkpro.com:8069/docs

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
86% confidence
Finding

This file documents a POST endpoint that accepts assessment data along with 'sessionId', optional 'userId', and timestamps, which are user/session-linked data elements. There is no accompanying description warning that this data will be transmitted to the service or explaining the privacy implications, so the API spec lacks disclosure for behavior that may affect user privacy.

Content

No source excerpt is available for this finding.

Vague Triggers

Low
Category
Not specified by scanner
Confidence
78% confidence
Finding

This is a manifest-style JSON file, so vague-trigger review applies. The description 'Generate personalized AR/VR developer roadmap' states the capability but does not define any activation scope, constraints, or exclusion conditions, which can make invocation matching overly broad in agent environments that use OpenAPI descriptions for tool selection.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.