Back to skill

Security audit

exam-timetable-architect

Security checks for vulnerabilities and agentic risk

Overview

This is a coherent exam study-planning skill that uses a local Python script and JSON plan file for disclosed scheduling behavior.

Install if you want a local exam timetable planner. Expect it to create and update a JSON plan file containing your exam dates, topics, and progress; use a dedicated --store path if you do not want that file next to the script.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
Findings (3)

Anti-Refusal Statement

High
Category
Anti-Refusal
Confidence
85% confidence
Finding

Skill instructs the agent to omit warnings, disclaimers, or ethical commentary. Stripping safety caveats hides risk from the user and is a common jailbreak preamble.

Content

Scanner excerpt · references/method.md (reported line 112)May include surrounding context.

md
- Always run the feasibility check before showing a plan; never present an
  over-capacity plan as-is.
- When the user says "I'm behind", run `replan`, don't moralize; the tool
  re-spaces from today automatically.
- Topics added mid-plan get spacing computed from their add date.
- If the user gives a syllabus dump (PDF/notes), extract topics into

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
90% confidence
Finding

The skill documents commands that read from and write to local files (exam_plan.json, JSON/CSV bulk input, and a Python script), but it does not declare any explicit tool scope or permissions boundaries. That creates ambiguity about what filesystem access the skill expects, increasing the chance of over-broad file access if the runtime grants default capabilities beyond the intended plan file.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

The usage triggers include broad natural-language phrases such as 'help me plan' and 'make me a study timetable,' which could cause the skill to be invoked in situations where the user did not intend this specific automation. In a skill that can read and write files or drive planning actions, over-triggering can lead to unintended state changes, confusion, or inappropriate use of user data.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.