Back to skill

Security audit

Skill

Security checks for vulnerabilities and agentic risk

Overview

TixFlow matches its event-ticketing purpose, but it combines ticket purchasing, NFT minting, wallet use, and calendar writes without clear consent and scoping safeguards.

Review this skill before installing. Treat ticket purchase, cNFT minting, wallet, waitlist, and calendar actions as sensitive: require explicit confirmation for each transaction or account change, verify prices and destination wallet details, and provide only the API keys you intend it to use. Prefer demo mode until the CrossMint/KYD, Google Calendar, and Maps behavior is fully documented and scoped.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
Findings (10)

Description-Behavior Mismatch

Medium
Category
Not specified by scanner
Confidence
97% confidence
Finding

The README documents CrossMint API use and real NFT ticket minting behavior that is not reflected in the manifest description, creating a transparency gap around wallet-affecting and purchase-related functionality. In an agent ecosystem, undeclared transactional capabilities are dangerous because users and reviewers may underestimate the skill’s ability to trigger real asset minting or payment flows.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The README advertises ticket purchasing and cNFT minting without any prominent warning that these actions can cause real purchases, wallet interactions, or irreversible on-chain effects. In the context of an AI agent skill for Telegram/Discord/WhatsApp, this increases the risk of users authorizing financial or blockchain actions without informed consent.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The skill advertises automatic ticket purchasing and Google Calendar synchronization without clearly warning that these actions can spend money, modify third-party accounts, and process personal data. In an agent context, ambiguous descriptions increase the chance of users or orchestrators invoking high-impact actions without informed consent, which can lead to unauthorized purchases or unwanted calendar changes.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The trigger list contains several short, generic phrases such as "buy ticket," "add to calendar," and especially "directions to" / "get directions" that are likely to appear in normal conversation and could activate the skill unintentionally. In this skill’s context, accidental activation is more dangerous than for a read-only utility because it can lead into ticket purchasing, calendar actions, route generation, or wallet-related flows involving external services and potentially user accounts or funds.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The manifest advertises sensitive capabilities including ticket purchase via cNFT minting, Google Calendar sync, directions lookup, event scraping, and wallet detection, but provides no user-facing warnings, consent language, or guardrails around data sharing, account access, third-party API usage, or financial effects. In this context, the absence of disclosures and friction is particularly risky because the skill combines wallet-related and purchase-related actions with external integrations that may expose personal data, modify user accounts, or initiate transactions.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
90% confidence
Finding

The syncToCalendar action takes a userEmail and is described as integrating with Google Calendar API, which is a privacy-relevant network operation involving personal data. While comments describe the integration, there is no user-facing disclosure, confirmation, or warning message associated with transmitting calendar/email data.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

Low
Category
Not specified by scanner
Confidence
89% confidence
Finding

The manifest describes the skill as integrating with KYD Labs protocol and Google Calendar, but the README also documents Google Maps API usage for transport directions. Directions may be a plausible event-assistant feature, but this additional third-party integration is not reflected in the manifest description.

Content

No source excerpt is available for this finding.

Scope Creep

Low
Category
Excessive Agency
Confidence
80% confidence
Finding

The phrase 'handle everything automatically' overstates agent autonomy for a skill that includes ticket purchasing and calendar updates. In this context, broad autonomy language can encourage unsafe invocation patterns or reduced human review for actions affecting finances and user accounts, even if no direct exploit is embedded in the markdown itself.

Content

Scanner excerpt · SKILL.md (reported line 25)May include surrounding context.

md
- 🎫 **Smart Booking** - Purchase tickets across platforms
- 📅 **Calendar Sync** - Sync events to Google Calendar with reminders
- ⏰ **Waitlist Management** - Get notified when sold-out events have availability
- 🤖 **AI Agent Power** - Let your agent handle everything automatically

## Installation

Unpinned Dependencies

Low
Category
Supply Chain
Confidence
93% confidence
Finding

The dependency is specified with a caret range (^120.0.0), which allows newer compatible versions to be installed over time. This weakens supply-chain reproducibility and can unintentionally pull in a vulnerable or breaking release without review, especially for a package that interfaces with external APIs and authentication flows.

Content

Scanner excerpt · package.json (reported line 21)May include surrounding context.

json
"author": "TixFlow Team",
  "license": "MIT",
  "dependencies": {
    "googleapis": "^120.0.0"
  }
}

Unverifiable Dependency: googleapis has 1 known advisory(ies) (GHSA-7543-mr7h-6v86 (Improper Authorization in googleapis)), but the manifest does not pin a version, so it is unknown whether the installed release is affected

Low
Category
Supply Chain
Confidence
84% confidence
Finding

The manifest includes googleapis without an exact pinned version, and the package has a known advisory history involving improper authorization. Because the allowed version range is not fixed, it is not possible to verify from this file alone whether installations will resolve to a safe release, creating avoidable uncertainty in a component likely to handle sensitive Google API access.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.