Back to skill

Security audit

schengen-clock

Security checks for vulnerabilities and agentic risk

Overview

This skill is a disclosed offline Schengen-day calculator that stores travel entries locally, with one correctness bug to consider but no evidence of malicious behavior.

Before relying on this for travel decisions, treat it as an offline arithmetic aid rather than legal advice, verify dates against official guidance, and be cautious with the traps command because planned future stays may be flagged too conservatively.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
Findings (3)

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
88% confidence
Finding

The skill appears to rely on reading and writing a local schengen.json file, but it does not explicitly declare any tool scope or permissions. That creates an authorization ambiguity: an agent platform may grant broader file capabilities than users expect, making local file access less transparent and harder to constrain or audit.

Content

No source excerpt is available for this finding.

Intent-Code Divergence

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

This is a true logic flaw: in the 'planned future stays' scan, the loop iterates over future stays already present in stays and then calls audit(stays, we, extra_stay=s), which adds that same stay a second time. That inflates calculated usage and can incorrectly label a lawful future trip as '[THIN MARGIN]' or '[OVER CAP]'. In this travel-compliance context, false overstay warnings can mislead users into canceling, shortening, or rescheduling legitimate travel plans based on incorrect legal-risk calculations.

Content

No source excerpt is available for this finding.

Vague Triggers

Low
Category
Not specified by scanner
Confidence
83% confidence
Finding

The description says to use the skill when the user travels or plans travel to Europe on a non-EU passport and must respect the Schengen 90/180 rule, but it does not define concrete trigger phrases or clear exclusion examples beyond a few unsupported cases. In a manifest/markdown context, this broad activation wording could cause the skill to be invoked for general Europe travel questions that are not specifically asking for Schengen-day calculations.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.