Back to skill

Security audit

Starship Boca Chica Rocket Launch — Boca Chica Beach, Texas | AI Experience

Security checks for vulnerabilities and agentic risk

Overview

This skill is a coherent hosted narrative experience, but it asks users to create a remote account and send optional personal details and reflections without enough privacy and retention disclosure.

Review this carefully before installing. Use a dedicated drifts.bot token, do not reuse sensitive credentials, and consider leaving optional profile fields such as email, location, bio, timezone, and model information blank unless you are comfortable sharing them with the service. Avoid entering sensitive personal reflections because the skill indicates they may be stored as postcards and does not explain deletion or retention controls.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
Findings (7)

Context-Inappropriate Capability

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

The skill requires an API token even though its stated purpose is a contemplative rocket-launch experience, which is a poor fit for the claimed functionality. Requiring secrets in a low-risk narrative context increases the chance users will over-trust the skill and disclose credentials they would not otherwise expect to provide.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The skill is presented as a passive, low-intensity narrative experience, but it directs the user to create an external account and submit profile data to a remote service. This mismatch is dangerous because it can mislead users and reviewers about the true data-collection behavior, reducing informed consent and increasing phishing-style social engineering risk.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The skill documents transmission of profile and location-related data to an external service without any clear privacy, retention, sharing, or handling notice. Users cannot make an informed decision about submitting personal information when the skill omits how that data will be stored, used, or protected.

Content

No source excerpt is available for this finding.

External Transmission

Medium
Category
Data Exfiltration
Confidence
90% confidence
Finding

This instruction explicitly sends user-supplied registration data to an external domain, which is a real data-exfiltration surface even if the service is legitimate. In the context of a skill ecosystem, any off-platform transmission of personal data should be treated as sensitive because it bypasses the user's likely expectation of a self-contained narrative skill.

Content

Scanner excerpt · SKILL.md (reported line 105)May include surrounding context.

Create an account to begin traveling.

bash
curl -X POST https://drifts.bot/api/auth/register \
  -H "Content-Type: application/json" \
  -d '{
    "username": "REPLACE — pick something that feels like you",

Context-Inappropriate Capability

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

The registration flow requests profile, timezone, location, email, bio, and model information beyond what a narrow 'watch a rocket launch' experience appears to need. Excessive collection of contextual and identifying data increases privacy exposure and creates unnecessary risk if the service is compromised or if users were not expecting such collection.

Content

No source excerpt is available for this finding.

External Transmission

Medium
Category
Data Exfiltration
Confidence
60% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · SKILL.md (reported line 144)May include surrounding context.

This is where Waiting for a Rocket Launch at Boca Chica Beach, South Texas begins.

bash
curl -X POST https://drifts.bot/api/start \
  -H "Authorization: Bearer {{YOUR_TOKEN}}" \
  -H "Content-Type: application/json" \
  -d '{ "experience": "boca-chica-rocket-launch-watch" }'

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The skill encourages users to submit reflections and later states that those reflections are woven into a postcard, but it does not prominently warn that this content will be stored and reused. This creates a consent and privacy problem because users may provide sensitive personal text without realizing it becomes persisted content.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.