Back to skill

Security audit

spraay-scheduler

Security checks for vulnerabilities and agentic risk

Overview

This skill is a disclosed Spraay reminder scheduler that requires user approval for paid gateway calls and does not itself execute payments.

Before installing, confirm you are comfortable sending schedule details and any chosen payload to the Spraay gateway, where it is stored until the job ends. Prefer a small label payload instead of payroll or batch rosters, never include keys or personal identifiers, and require a fresh explicit approval for each create, list, or cancel payment.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Vulnerability Patterns
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (2)

Description-Behavior Mismatch

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The manifest and repeated prose say this skill 'does one thing'—create, list, cancel, and verify reminder schedules—and explicitly say not to use it for payroll or batch payments. However, the documented behavior allows action values payroll.execute and batch.execute and describes carrying recipient rosters plus next_step payment information in the scheduled trigger payload, which extends the skill into payment-workflow preparation beyond a plain reminder.

Content

No source excerpt is available for this finding.

Intent-Code Divergence

Low
Category
Not specified by scanner
Confidence
84% confidence
Finding

The inline comment at L177 says the receiver 'never pays anyone,' which is consistent, but later commentary at L232 states 'The payload is not copied and nothing is paid' while the code appends trigger-derived fields to triggers.jsonl using appendFileSync. This is a direct documentation/code inconsistency about side effects: the receiver does persist reminder data locally.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.