Back to skill

Security audit

Uplo Facilities

Security checks for vulnerabilities and agentic risk

Overview

This facilities knowledge skill is coherent and disclosed, but its full organizational context export should be treated as sensitive.

Install only with a UPLO token scoped to facilities data. Prefer targeted searches over full organization exports, confirm that UPLO enforces identity and classification controls, and handle exported context as sensitive operational information.

Vulnerability Patterns
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (1)

Context-Inappropriate Capability

Medium
Confidence
94% confidence
Finding
The manifest exposes an `export_org_context` capability even though the stated purpose is facilities knowledge search and structured extraction. That capability can enable bulk access or exfiltration of broader organizational context than is necessary for building-management workflows, violating least-privilege and increasing the blast radius if the skill is misused or compromised.

Static analysis

No suspicious patterns detected.