Back to skill

Security audit

Kyndlo Events

Security checks for vulnerabilities and agentic risk

Overview

This skill appears purpose-built for Kyndlo event work, but it gives an agent broad live-system authority with under-scoped remote instructions and destructive/admin commands.

Install only if you trust the Kyndlo CLI package, the Kyndlo dashboard administrators, and the token permissions. Prefer a least-privilege token, review dashboard rules before batches, avoid pasting secrets into chat or logs, and do not use the admin/update/delete examples unless you explicitly intend those live changes.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
Findings (3)

T08 · Insecure Dependencies

Warning
Location
SKILL.md:14
Finding

Unpinned Global Installation of an Executable npm Dependency

Content
View full analysis
Remediation
View remediation

T01 · Skill Instruction Hijacking

Error
Location
SKILL.md:116
Finding

Untrusted Remote Dashboard Content Is Adopted as Mandatory Agent Instructions

Content
View full analysis
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Error
Location
SKILL.md:258
Finding

Untrusted Values Are Interpolated into Shell Command Templates

Content
View full analysis
in County, " --json --limit 5 --region US ``` Event data obtained from APIs, websites, and remote rules is similarly interpolated: ```bash gokyn event create \ --title "" \ --description "<2-3 sentence description per rules>" \ --activity :1 \ --start-date-time "2027-01-01T09:00:00Z" \ --end-date-time "2028-01-01T23:59:00Z" \ --timezone "" \ --location-type physical \ --location-place "" \ --location-address "" \ --location-lat \ --location-lng="" \ --recurring \ --recurrence-frequency weekly \ --recurrence-interval 1 \ --recurrence-days "" \ --is-public=false \ --is-premium-only \ --is-active=false \ --price \ --price-currency USD \ --booking-url "" \ --json ``` The image prompt also contains researched and remotely sourced values: ```bash gokyn image generate \ --prompt "A welcoming with , inviting for casual social meetups. Inspired by in , ." \ --event-id ``` Validation data is inserted into single-quoted JSON passed through the shell: ```bash gokyn validation submit --status invalid \ --issues-json '[{"field":"","severity":"","description":"","currentValue":"","expectedValue":""}]' ``` ### Technical Analysis These templates include values originating from users, Kyndlo API responses, Google Places responses, websites, generated descriptions, and remotely managed rules. Enclosing a placeholder in ...[truncated 2419 chars]
Remediation
View remediation
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
Findings (6)

Context-Inappropriate Capability

High
Category
Not specified by scanner
Confidence
99% confidence
Finding

Including gokyn event delete <eventId> gives the skill destructive authority that is unnecessary for creating or validating events from campaign tasks. If followed by an agent or triggered through prompt confusion, it could delete legitimate production data irreversibly or at scale.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

The invocation guidance uses broad phrases like 'create events' or 'generate events', which can overlap with ordinary conversation and unintentionally trigger this powerful workflow. Because the skill can claim tasks, create records, and alter system state, ambiguous activation increases the risk of unintended execution.

Content

No source excerpt is available for this finding.

Autonomous Decision Making

Medium
Category
Excessive Agency
Confidence
88% confidence
Finding

The skill directs the agent to execute commands immediately without first asking the user anything, enabling autonomous stateful actions before fresh confirmation. In a skill that can claim tasks, create events, and modify backend records, this weakens human oversight and increases the risk of unintended operations.

Content

Scanner excerpt · SKILL.md (reported line 61)May include surrounding context.

Step 1: Verify token

Action: Run this command immediately — do not ask the user anything first.

bash
gokyn whoami --json

Description-Behavior Mismatch

Medium
Category
Not specified by scanner
Confidence
98% confidence
Finding

The skill presents itself as a tightly scoped event-creation and validation workflow, but later exposes unrelated administrative powers including state registration, campaign seeding, event updates, and deletion. This scope expansion violates least privilege and can cause an invoking agent or user to perform destructive or admin-only actions that were not justified by the skill’s stated purpose.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

State registration and campaign seeding are bootstrap/administrative functions unrelated to ordinary event creation and validation. Their presence broadens the operational authority of the skill and creates a path for accidental or unauthorized modification of campaign/task state.

Content

No source excerpt is available for this finding.

Missing User Warnings

Low
Category
Not specified by scanner
Confidence
82% confidence
Finding

The setup section instructs users to export sensitive API tokens but provides no warning about secret handling, shell history, logging, or avoiding disclosure back to the model. While common in CLI docs, this still increases the chance of credential exposure in shared terminals, transcripts, or support logs.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.