Back to skill

Security audit

gift-occasion-planner

Security checks for vulnerabilities and agentic risk

Overview

This is a local gift-planning skill with some documentation and behavior mismatches, but no evidence of hidden access, exfiltration, persistence, or unsafe execution.

Reasonable to install if you want a local gift planner. Review the generated gifts.json and ICS files before sharing or importing them into a cloud-synced calendar, because they may contain personal notes, budgets, interests, and taboo gift information. Treat one-time occasions cautiously because the current script may make them recur annually.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Vulnerability Patterns
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
Findings (4)

Tp4

High
Category
MCP Tool Poisoning
Confidence
93% confidence
Finding

The code largely matches the declared gift-planner purpose: it stores people and occasions, computes upcoming occasions, generates recommendations avoiding near-duplicates and taboo items, tracks budgets, logs gifts, and exports calendar reminders. However, the description is not fully accurate. The ICS feature is described as exporting reminders at 21/7/1 days out, but the code exports at 60/21/7/1 days. The declared per-person gift profile includes interests, sizes, favorites, taboo list, and past gifts; the code supports interests, sizes, taboo, notes, and uses a separate global history log rather than a per-person embedded past-gifts profile, with no favorites field. The buying plan is described as including what, budget, where, wrap, and card, but the stored plan only captures idea/where/cost/status and renders generic wrap/card guidance rather than structured fields. Also, add-occasion advertises one-time dates, but occurrence calculation ignores the stored year, so behavior is not exactly as implied. These are material description-versus-behavior differences, though the overall primary purpose remains aligned.

Content

No source excerpt is available for this finding.

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
70% confidence
Finding

Without declared permissions the skill's intent is opaque and cannot be validated.

Content

No source excerpt is available for this finding.

Intent-Code Divergence

Medium
Category
Not specified by scanner
Confidence
98% confidence
Finding

The CLI help text says --date is for one-time occasions, implying the year matters and the event should not recur. However, the implementation strips the month and day into occ['month_day'] and next_occurrence ignores the stored year, causing the occasion to recur annually.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

Low
Category
Not specified by scanner
Confidence
95% confidence
Finding

The manifest description specifically says the skill exports ICS reminders at 21, 7, and 1 days before an occasion. The implementation emits reminders at 60, 21, 7, and 1 days, so the exported behavior is broader than the stated description.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.