Back to skill

Security audit

Pin Seeker — Golf Tee Times

Security checks for vulnerabilities and agentic risk

Overview

This skill is a straightforward tee-time search helper that sends golf search queries to a hosted service and does not show hidden persistence, booking, payment, or destructive behavior.

Install only if you are comfortable sending tee-time search details such as location, date, party size, and timezone to Pin Seeker. Do not treat results as reservations; the skill is designed to provide GolfNow links for the user to complete booking separately.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
Findings (4)

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
90% confidence
Finding

The skill invokes shell-based capabilities (curl, bundled search.sh) but does not declare any explicit tool scope or allowed-tools restrictions. This increases the risk that an agent runtime grants broader shell access than necessary, enabling unintended command execution paths beyond the intended HTTP search operation.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
88% confidence
Finding

The manifest says to use the skill when asked about 'golf', 'weekend golf', or 'comparing courses', which are broad natural-language triggers rather than narrowly scoped invocation conditions. This can cause unintended activation for general golf discussion instead of specific tee-time lookup tasks.

Content

No source excerpt is available for this finding.

Skill Enumeration

Medium
Category
Agent Snooping
Confidence
80% confidence
Finding

Skill enumerates or reads other installed skills. Access to other skills' SKILL.md files or the skills directory reveals prompt instructions, capabilities, and secrets that should be invisible to peer skills.

Content

Scanner excerpt · SKILL.md (reported line 45)May include surrounding context.

Hermes:

bash
hermes skills install https://pinseeker.xyz/skills/pin-seeker/SKILL.md

Production search: https://pinseeker.xyz/api/agent/search

Missing User Warnings

Low
Category
Not specified by scanner
Confidence
89% confidence
Finding

The script sends the user’s natural-language query, and optionally their timezone, to a remote third-party service without any explicit disclosure beyond minimal CLI usage text. While this is expected for a search skill, it still creates a privacy risk because users may include sensitive location, schedule, or personal details in free-form queries that are transmitted off-host.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.