Back to skill

Security audit

party-guest-optimizer

Security checks for vulnerabilities and agentic risk

Overview

This is a local party-planning helper whose relationship-sensitive output is expected for its purpose, with no evidence of hidden network access, credential use, or persistence.

Install only if you are comfortable entering guest relationships, tensions, interests, and invite decisions into local JSON files and seeing those results printed in the terminal. Keep generated reports private, and be aware that the advertised pods option appears incomplete.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Vulnerability Patterns
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
Findings (6)

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
84% confidence
Finding

The skill advertises no explicit tool scope or permission boundaries, yet the analyzer detected file-write capability in the associated implementation. That mismatch is dangerous because an agent may invoke the skill without a clear least-privilege contract, allowing unexpected filesystem modification such as overwriting local files, creating artifacts in unsafe locations, or persisting sensitive party data without the user's informed consent.

Content

No source excerpt is available for this finding.

Intent-Code Divergence

Medium
Category
Not specified by scanner
Confidence
98% confidence
Finding

The module docstring claims the seat subcommand supports "round/long table or pods," which suggests a distinct seating mode for pods. In the actual code, cmd_seat only uses args.round to choose between round and long-table behavior, and args.pods is parsed but never referenced, so the documented capability is not implemented.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
83% confidence
Finding

This code outputs isolation risks, social clusters, tension pairs, and shared interests for named guests, which can expose sensitive interpersonal and preference data. Although printing results is central to the tool, there is no visible disclosure in the code warning users that the analysis will reveal personal relationship information in terminal output.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
80% confidence
Finding

The command prints a list of selected and excluded guests by identifier, effectively revealing ranking-style judgments about who should be omitted. Because this output could be socially sensitive if seen by others, the code should provide some disclosure that the results are advisory and may expose sensitive invitation decisions.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
78% confidence
Finding

This output can reveal socially sensitive inferences, including adjacency choices driven by conflicts and shared-interest matchmaking between specific guests. There is no explicit disclosure that generating a seating chart will expose personal relationship data in the console.

Content

No source excerpt is available for this finding.

Intent-Code Divergence

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

Adding a dedicated --pods argument implies the seat command can optimize seating into pods. However, no later code reads args.pods, so users are offered a capability the program does not actually perform.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.