PCO CLI - Planning Center Services

Security checks across malware telemetry and agentic risk

Overview

This Planning Center skill is not malicious, but it needs review because it relies on unreviewed local code and can modify or delete live church planning data.

Install only if you trust and have reviewed the external pco.ts CLI that this skill runs. Use least-privilege Planning Center credentials where possible, and require explicit human confirmation before any raw POST, PATCH, or DELETE command.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (2)

Intent-Code Divergence

Medium
Confidence
89% confidence
Finding
The documentation says the CLI is for PCO Services only, but it also exposes a generic raw API interface that can issue arbitrary POST, PATCH, and DELETE requests. This mismatch can mislead users or downstream agents into assuming the tool is read-oriented or scoped more narrowly than it really is, increasing the risk of unintended writes or deletions against live Planning Center data.

Missing User Warnings

Medium
Confidence
95% confidence
Finding
The skill includes destructive API examples, including PATCH and DELETE, without any safety warning, confirmation requirement, or guidance about operating on production church data. In an agent or automation context, examples often become copied behavior, so omission of cautions materially raises the chance of accidental data modification or deletion.

VirusTotal

65/65 vendors flagged this skill as clean.

View on VirusTotal