Back to skill

Security audit

Appointment Manager

Security checks for vulnerabilities and agentic risk

Overview

This appointment skill has a coherent purpose, but it expects to store and transmit sensitive appointment and medical-adjacent data with broader authority than its manifest clearly declares.

Review this before installing. It is not evidence of malware, but it should only be used if you are comfortable with the agent keeping appointment and provider history in local Markdown files, sending reminders through configured channels, using calendar access, and entering personal details into booking sites. Prefer explicit confirmation before any booking, cancellation, calendar update, or transmission of DOB, medical reason, address, or follow-up notes.

Vulnerability Patterns
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
Findings (3)

T09 · Insecure Skill Coding Practices

Warning
Location
SKILL.md:65
Finding

Plaintext Persistence of Sensitive Personal and Medical Information

Content
View full analysis
Remediation
View remediation

T05 · Unauthorized Access and Privilege Escalation

Warning
Location
SKILL.md:6
Finding

Declared Tool Permissions Do Not Match Required Privileged Operations

Content
View full analysis
", "to": "" } } ``` Repeat for 2h reminder. Store cron job IDs in appointments.md. ``` ```md ## Reschedule flow `/appt reschedule [appointment]` 1. Cancel existing reminder cron jobs 2. Navigate back to booking system (for online bookings) 3. Find new slot — present options 4. Complete reschedule 5. Update appointments.md 6. Register new reminder cron jobs 7. Update Google Calendar event ``` ### Technical Analysis The skill manifest declares only `web_fetch` and `web_search`, but its operational instructions require subs ...[truncated 2052 chars]
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Warning
Location
SKILL.md:105
Finding

Sensitive Booking Data May Be Submitted to Unverified External Websites

Content
View full analysis
Remediation
View remediation
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
Findings (8)

Missing User Warnings

High
Category
Not specified by scanner
Confidence
96% confidence
Finding

The skill is designed to collect and store sensitive personal and health-related appointment data in local markdown files without prominently warning the user. Because the stored data includes medical providers, appointment history, addresses, notes, and potentially date of birth or referrals, lack of disclosure materially increases privacy and compliance risk.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The trigger list includes broad terms such as doctor and dentist, which can cause unintended invocation in ordinary conversation. In a skill that stores sensitive medical and appointment data and may initiate web actions, accidental activation increases privacy and action-taking risk.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

The skill states that online booking is handled automatically but does not clearly warn that it may submit user-provided personal data to third-party booking websites and calendar systems. Without explicit notice and consent, users may not understand that external services will receive their identifying or health-related information.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The skill instructs the agent to check and update Google Calendar despite only declaring web_search and web_fetch as allowed tools. This creates a permission/specification mismatch that can lead to unsafe assumptions, failed enforcement, or pressure to use undeclared capabilities for calendar access and modification.

Content

No source excerpt is available for this finding.

Ssd 3

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

The skill persistently stores appointment details, provider information, confirmation references, prep notes, and follow-up notes in plain-language files and later reuses them in reminders. In this context, the data can reveal medical conditions, treatment patterns, location history, and other sensitive personal information, making plaintext retention and replay especially risky.

Content

No source excerpt is available for this finding.

Ssd 3

Medium
Category
Not specified by scanner
Confidence
90% confidence
Finding

The phone-script workflow instructs the agent to compile personal and potentially medical details, including name, date of birth, reason for visit, and availability, into a single message for reuse. Consolidating this information into one outbound message increases exposure if the message is misdelivered, logged, or viewed by others on the user's channel.

Content

No source excerpt is available for this finding.

Ssd 3

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The structured memory design explicitly accumulates long-term appointment, provider, status, follow-up, and notes data across time. In a life-admin and health-adjacent context, such longitudinal records substantially increase harm from unauthorized access because they can expose routines, medical relationships, and historical sensitive events.

Content

No source excerpt is available for this finding.

Intent-Code Divergence

Low
Category
Not specified by scanner
Confidence
88% confidence
Finding

The text states that online booking requires no action beyond the initial request, yet later sections require the user to choose among providers and slots and sometimes supply required personal details. This is an active contradiction in the skill's own documentation about how autonomous the flow really is.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.