Back to skill

Security audit

Upcoming Concerts

Security checks for vulnerabilities and agentic risk

Overview

This skill does what it says: it uses a user-provided Ticketmaster API key to fetch concert listings and prints the results.

Install only if you are comfortable providing a Ticketmaster API key and allowing the skill to query Ticketmaster for the searches you ask it to run. A stricter manifest that declares the exact API domain and environment variable would improve containment, but the current artifacts are coherent and narrowly scoped.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Vulnerability Patterns
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (1)

Lp3

Medium
Category
MCP Least Privilege
Confidence
88% confidence
Finding
The skill invokes a Python script that requires both environment-variable access and outbound network access, but the manifest does not declare any explicit tool scope such as permissions or allowed-tools. This creates a trust and containment gap: a runtime may grant broader capabilities than the user expects, and the skill can access the Ticketmaster API key and make network requests without a clearly declared security boundary.

Static analysis

No suspicious patterns detected.