Back to skill

Security audit

KPLC Sentinel

Security checks for vulnerabilities and agentic risk

Overview

The skill is mostly coherent for tracking KPLC electricity usage, but it retains sensitive token/SMS and household data and can trigger automatic reminder/calendar side effects without enough user control.

Review this skill before installing if you forward real KPLC SMS messages. It keeps detailed household electricity records locally, including full tokens and raw SMS text, and it may create reminders or calendar events through other skills. Use a restricted account, pin dependencies, and avoid enabling payment/calendar/reminder integrations unless you want those side effects.

Vulnerability Patterns
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
Findings (3)

T08 · Insecure Dependencies

Warning
Location
requirements.txt:1
Finding

Unpinned Third-Party Dependency Creates a Supply-Chain Risk

Content
View full analysis
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Warning
Location
logic.py:30
Finding

Full Prepaid Electricity Tokens and Raw SMS Messages Are Retained in Plaintext

Content
View full analysis
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Warning
Location
logic.py:403
Finding

Predictable Shared Temporary Cache Allows Local PDF Substitution

Content
View full analysis
Remediation
View remediation
Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
Findings (19)

Tp4

High
Category
MCP Tool Poisoning
Confidence
95% confidence
Finding

The skill description understates important behaviors, including network retrieval, persistent local storage, and additional analytics features. When a skill stores user utility data or reaches out to external services without clearly declaring that behavior, users and host agents cannot make informed trust decisions, and reviewers may miss privacy and data-handling risks.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
96% confidence
Finding

The skill description understates important behaviors, including network retrieval, persistent local storage, and additional analytics features. When a skill stores user utility data or reaches out to external services without clearly declaring that behavior, users and host agents cannot make informed trust decisions, and reviewers may miss privacy and data-handling risks.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

The README says the skill collects household size, area/estate, appliance lists, and forwarded KPLC SMS data, but it does not clearly frame these as sensitive personal data or warn users about the privacy implications. In this context, the combined data can reveal occupancy patterns, approximate income/spending behavior, and when a home may be unoccupied or nearing outage, which increases privacy and safety risk if mishandled or shared across channels or other skills.

Content

No source excerpt is available for this finding.

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
90% confidence
Finding

The skill explicitly instructs the agent to run local shell commands and references outbound outage checks, yet it declares no tool scope or permissions. This creates an authorization gap where the agent may use shell or network capabilities without an explicit least-privilege contract, increasing the chance of unintended command execution or data egress.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

The skill tells the agent to create reminders and possibly calendar events automatically when outages are found, without requiring explicit user confirmation. This can cause unauthorized side effects in user-integrated systems, leak sensitive location/schedule information into calendars or reminder stores, and normalize silent cross-tool actions.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The skill instructs the agent to offer initiating an M-Pesa payment flow when balance is critically low, but it does not define a strong user-confirmation boundary or payment safety warning. Payment initiation is a high-sensitivity action; if triggered too eagerly or routed through another installed payments skill, it could lead to unauthorized or socially engineered financial transactions.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The skill hard-codes a specific persona and dialect style ('casual English with occasional Sheng/Swahili flavor') without any indication that the user opted into that communication mode. This can override user preferences, reduce accessibility or professionalism in some contexts, and create an unnecessary prompt-level constraint that may conflict with user expectations or platform policy.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
88% confidence
Finding

The skill automatically parses any message that looks like a KPLC SMS and stores token, units, amount, and raw message text before obtaining user confirmation or presenting a privacy notice. This can lead to unintended retention of billing and location-adjacent utility data when users forward messages casually or when unrelated content is misclassified as a KPLC SMS.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The reset command immediately clears the user profile and restarts onboarding without any confirmation step, warning, or undo path. In a chat interface, accidental triggers, spoofed messages, or ambiguous user input can cause irreversible loss of household and budgeting data, degrading availability and integrity of user data.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The reset_profile function deletes all rows from the profile table, which is an irreversible data-loss operation, but there is no confirmation prompt, user-facing warning, or explicit disclosure near the operation. The docstring describes the behavior for developers, but it is not a user warning.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

The budget messages include Swahili phrases such as "Umepita budget" without any indication that the user opted into that language or that alternative locales are supported. This is a natural-language locale policy issue because the skill imposes a specific language style on all users.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
89% confidence
Finding

The comparison insights messages include Swahili text such as "Poa" and "Usage ni sawa sawa" in normal user output, but the file contains no mechanism for choosing or configuring language. That creates the same language-policy concern of forcing a locale-specific style on users.

Content

No source excerpt is available for this finding.

Missing User Warnings

Low
Category
Not specified by scanner
Confidence
87% confidence
Finding

The heartbeat section documents background checks and proactive alerts, but the README does not prominently warn users that the skill will send automatic messages and reminders without a fresh request each time. In a messaging-agent context, this can surprise users, create unwanted notifications, and leak household routines or outage-related information to anyone with access to the chat device or channel.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
77% confidence
Finding

All non-SMS interactions are rejected unless they begin with the fixed prefix "stima", creating a locale-specific interaction requirement. The file does not indicate that users may choose an alternative language or prefix, nor does it document this as a justified region-specific constraint.

Content

No source excerpt is available for this finding.

Missing User Warnings

Low
Category
Not specified by scanner
Confidence
90% confidence
Finding

The code creates a new SQLite file if it does not exist and opens it for schema initialization, which modifies the local filesystem. While there is an internal comment about permission restriction, there is no user-facing confirmation, log message, or disclosure indicating that running this file will create and write a database file.

Content

No source excerpt is available for this finding.

Missing User Warnings

Low
Category
Not specified by scanner
Confidence
83% confidence
Finding

This function fetches a PDF from an external KPLC website and writes it to local temporary storage, but the code only logs failures and does not include any user-facing warning or disclosure about the outbound network access and local file caching. Because this skill file handles user profile data elsewhere, users may reasonably expect notice when external retrieval is performed.

Content

No source excerpt is available for this finding.

Unpinned Dependencies

Low
Category
Supply Chain
Confidence
97% confidence
Finding

The dependency is unpinned: pdfplumber is specified without a version constraint, so installs may pull different versions over time. This can introduce vulnerable or breaking upstream releases into the skill unpredictably, weakening reproducibility and supply-chain security.

Content

Scanner excerpt · requirements.txt (reported line 1)May include surrounding context.

text
pdfplumber

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
91% confidence
Finding

The alert message is written with the locale-specific greeting "Niaje!", which assumes a particular linguistic/cultural context for all users. The file provides no indication that users can choose their preferred language or locale, so this is a natural-language policy concern.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
91% confidence
Finding

This prompt also begins with "Niaje!" and uses region-specific meter instructions, but the file does not show any user language selection or documented locale constraint. Without explicit opt-in or clear region-specific justification in the skill, this may violate language/locale policy expectations.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.