Back to skill

Security audit

Luma Event Manager

Security checks for vulnerabilities and agentic risk

Overview

This Luma skill is coherent but should go to Review because it uses raw session cookies to access private data and can change RSVPs or calendars without clear confirmation controls.

Install only if you are comfortable giving the skill ongoing access to your Luma session cookies and letting it read private event/guest-list data. Treat the cookies in pass like a password, use RSVP and calendar tools only after reviewing the exact event/action, and consider updating dependencies before use.

Vulnerability Patterns
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (1)

T09 · Insecure Skill Coding Practices

Warning
Location
src/rsvp.ts:146
Finding

Speculative RSVP Endpoint Probing Can Cause Repeated Authenticated State Changes

Content
View full analysis
> { const payloads: Array> = [ { event_id: eventId, response }, { event_id: eventId, status: response }, { event_id: eventId, answer: response }, { event_id: eventId, rsvp: response }, { event_id: eventId, value: response }, { event_id: eventId, event_uuid: eventId, response }, ]; if (response === 'yes') { payloads.push({ event_id: eventId, going: true }); } if (response === 'no') { payloads.push({ event_id: eventId, going: false }); } return payloads; } ``` ```ts const endpoints = [ `${LUMA_BASE_URL}/api/v2/event/rsvp`, `${LUMA_BASE_URL}/api/v1/event/rsvp`, `${LUMA_BASE_URL}/api/event/rsvp`, `${LUMA_BASE_URL}/api/v2/event/${eventId}/rsvp`, `${LUMA_BASE_URL}/api/v1/event/${eventId}/rsvp`, `${LUMA_BASE_URL}/api/rsvp`, ]; const payloads = buildPayloads(eventId, normalized); for (const endpoint of endpoints) { for (const payload of payloads) { const headers: Record = { 'User-Agent': USER_AGENT, 'Accept': 'application/json, text/plain, */*', 'Content-Type': 'application/json', 'X-Requested-With': 'XMLHttpRequest', 'Cookie': cookies, }; if (csrfToken) { headers['x-csrf-token'] = csrfToken; headers['x-csrf'] = csrfToken; } const responseResult = await fetchWithBackoff( endpoint, { method: 'POST', headers, body: JSON.stringify(payload), }, LUMA_BACKOFF_OPTIONS ); const text = await responseResult.text(); if (responseResult.ok) { return { success: true, messag ...[truncated 3538 chars]
Remediation
View remediation
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
Findings (32)

Known Vulnerable Dependency: undici==7.19.2 — 16 advisory(ies): CVE-2026-1525 (Undici has an HTTP Request/Response Smuggling issue); CVE-2026-6733 (undici vulnerable to HTTP response queue poisoning via keep-alive socket reuse); CVE-2026-1527 (Undici has CRLF Injection in undici via `upgrade` option) +13 more

High
Category
Supply Chain
Confidence
94% confidence
Finding

The lockfile pins undici to version 7.19.2, and the provided advisory set indicates multiple known high-severity issues including request/response smuggling, response queue poisoning, and CRLF injection. Even though this dependency is transitive through cheerio, shipping a version with known network-protocol vulnerabilities can expose the skill if it fetches remote content or processes attacker-influenced HTTP interactions.

Content

No source excerpt is available for this finding.

Intent-Code Divergence

High
Category
Not specified by scanner
Confidence
98% confidence
Finding

The module claims to be a web scraper, but it also retrieves authentication material from the local password store by executing a system command. Hidden credential access materially expands the trust boundary of the skill and can surprise users or calling agents, enabling unauthorized use of stored session cookies for authenticated scraping.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

High
Category
Not specified by scanner
Confidence
99% confidence
Finding

The code has an unjustified capability to execute a local shell command (pass show luma/cookies) to access stored credentials, even though its stated purpose is scraping pages. Shell execution plus secret access is a dangerous combination because it allows the skill to cross from remote data retrieval into local system and credential access, increasing the blast radius if misused or later modified.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The design explicitly relies on authenticated scraping using exported browser cookies to access private Luma data, but it does not pair that with clear user-facing warnings about privacy exposure, account misuse risk, or possible violations of service expectations. Handling session cookies as a setup step materially increases the chance of credential-like secret leakage or unintended account access if users do not understand the sensitivity of those tokens.

Content

No source excerpt is available for this finding.

Autonomous Decision Making

Medium
Category
Excessive Agency
Confidence
75% confidence
Finding

Skill enables autonomous high-impact decisions without human-in-the-loop verification. Critical operations (destructive commands, financial transactions, data deletion) should require explicit user confirmation.

Content

Scanner excerpt · LUMA_SKILL_DESIGN.md (reported line 25)May include surrounding context.

md
### 1.3 Problem Statement
- Event management requires constant app switching (Luma ↔ Calendar ↔ WhatsApp)
- Geographic event discovery is manual and time-consuming
- Attendees miss updates and event details without checking the app
- Hosts lack quick access to attendance metrics without logging into Luma

### 1.4 Solution

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

The skill advertises RSVP submission and Google Calendar sync, both of which perform state-changing actions in third-party services, yet the document does not clearly warn users that the agent can modify external accounts on their behalf. Without prominent disclosure and confirmation requirements, users may trigger unintended RSVPs or calendar writes and misunderstand the scope of agent authority.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
89% confidence
Finding

The README advertises access to guest lists and authenticated scraping via copied session cookies, but does not include a clear privacy and data-handling warning. Guest lists can contain personal information about third parties, and instructing users to extract browser session cookies normalizes handling sensitive credentials and other people's data without adequate safeguards or consent guidance. In this skill context, that makes the issue more serious than a generic scraping tool because the documented features explicitly target account-authenticated event and attendee data.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
93% confidence
Finding

The README instructs users to run npx clawdhub install luma without pinning a specific version. This can cause users to execute whatever version is currently published, increasing supply-chain risk if the package is compromised or a malicious version is later released. In the context of an install command, this is a real security concern because it directly affects first-run code execution on the user's machine.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The skill explicitly instructs users to extract live browser session cookies (luma_session, luma_user_id) and store them for later reuse, but it does not warn that these values function as bearer credentials that can grant account access if exposed. Because the skill enables authenticated actions like viewing private RSVP data, guest lists, and submitting RSVPs via web scraping, mishandling these cookies could lead to account compromise or unauthorized access to private event information.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
87% confidence
Finding

The tool descriptions are broadly phrased and do not define when the agent should ask for confirmation, verify user intent, or limit use of high-impact operations. This increases the chance that an agent will invoke actions such as RSVP changes, calendar modification, host event inspection, or configuration flows based on ambiguous prompts or weak inference rather than explicit authorization.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

The manifest exposes privacy- and integrity-impacting capabilities, including viewing hosted guest lists, changing RSVP status, adding events to Google Calendar, and configuring API access, but provides no user-facing warnings or confirmation requirements. In an agent setting, this can lead to unintended disclosure of attendee data or unauthorized state changes if the assistant acts on incomplete, indirect, or manipulated instructions.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

This function creates calendar events by invoking an external CLI and performs a state-changing action without any built-in user confirmation, approval gate, or visible warning at the point of execution. In an agent/skill context, untrusted or loosely validated event data could cause silent creation of calendar entries in the user's Google account, enabling spam, nuisance, or manipulation of a user's schedule.

Content

No source excerpt is available for this finding.

Intent-Code Divergence

Medium
Category
Not specified by scanner
Confidence
98% confidence
Finding

The handler is exposed as luma_events_on and accepts a date, which implies date-constrained results. However, the implementation calls scrapeDiscover({}) with no date filtering and returns all upcoming events, explicitly noting that filtering is not implemented yet.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
87% confidence
Finding

This function performs an external side effect by writing to Google Calendar immediately after being invoked, with no confirmation or explicit warning at this layer. In an agent setting, ambiguous user requests or prompt-influenced tool calls could cause unintended calendar modifications, which is especially risky because the skill bridges scraped event data into a third-party account.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

The function accepts raw authentication cookies and sends them in outbound requests, but there is no evidence in this module of consent checks, scoping, or safeguards around how those credentials are obtained and used. This is dangerous because misuse of the function or unsafe integration can cause authenticated actions to be taken with a user's session material, potentially exposing or abusing account access.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

This code performs authenticated, state-changing actions on behalf of a user by sending their cookies to multiple inferred RSVP endpoints and trying several payload formats until one succeeds. That creates a real security concern because it automates account actions and endpoint probing without visible guardrails, increasing the chance of unauthorized or unintended interaction with the user's Luma account if upstream callers supply cookies or slugs unsafely.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The authenticated scraping functions accept cookies and pass them into HTTP requests to /home, /home/manage, and similar endpoints, which transmits session credentials and accesses account-scoped data. While the comments note 'requires auth', there is no user-facing confirmation, warning, or explicit disclosure about using session cookies or accessing private account data.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

The guest-list scraper accesses attendee data that may be private or visibility-restricted, using authenticated session cookies, without any explicit in-code warning, consent check, or access-control guardrail. In a skill context, collecting third-party attendee information raises privacy and data-minimization concerns beyond ordinary event scraping.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
97% confidence
Finding

The skill silently retrieves session cookies from a local password store using shell execution, with no visible disclosure to the user or caller. Even if the command is fixed, this covert credential loading bypasses informed consent and can enable authenticated actions under the user's identity without a clear trust decision.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
90% confidence
Finding

The luma_rsvp tool performs a state-changing action that can alter a user's RSVP status, but its schema and description provide no indication that confirmation or an explicit warning is required before execution. In an agent setting, this increases the risk of unintended attendance changes from ambiguous prompts, over-eager automation, or prompt injection that tricks the agent into taking an action on the user's behalf.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

The luma_add_calendar tool modifies an external Google Calendar but exposes no warning, confirmation requirement, or side-effect annotation in the type definition. Because it can create calendar entries tied to a user account, an agent could invoke it without sufficiently informed consent, causing unwanted calendar pollution or social/operational disruption.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
90% confidence
Finding

The geocoding helper sends user-supplied location text to the external Nominatim service, which can expose sensitive user location data to a third party without any consent, minimization, or notice at this layer. In an event/location skill, users may reasonably provide home, work, or private venue addresses, so silent transmission creates a real privacy risk.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The configuration check imports child_process and invokes a shell command (pass show luma/api_key 2>/dev/null) to determine whether a secret exists. Even though the command string is constant, using shell execution in a utility module increases attack surface, creates an unnecessary dependency on a shell and external binary, and can become dangerous if later modified to incorporate variable input or run in restricted environments.

Content

No source excerpt is available for this finding.

Unpinned Dependencies

Low
Category
Supply Chain
Confidence
40% confidence
Finding

Dependencies lack version pinning, allowing potential malicious package updates. Consider pinning versions.

Content

Scanner excerpt · package.json (reported line 22)May include surrounding context.

json
"author": "",
  "license": "MIT",
  "dependencies": {
    "cheerio": "^1.2.0"
  },
  "devDependencies": {
    "@types/node": "^20.19.30",

Unpinned Dependencies

Low
Category
Supply Chain
Confidence
40% confidence
Finding

Dependencies lack version pinning, allowing potential malicious package updates. Consider pinning versions.

Content

Scanner excerpt · package.json (reported line 25)May include surrounding context.

json
"cheerio": "^1.2.0"
  },
  "devDependencies": {
    "@types/node": "^20.19.30",
    "typescript": "^5.9.3"
  }
}

Static analysis

No suspicious patterns detected.