Back to skill

Security audit

Operations Schedule Builder

Security checks for vulnerabilities and agentic risk

Overview

This skill coherently builds a local task schedule and writes a local CSV receipt without network access, credentials, persistence, or hidden high-impact behavior.

Before installing, confirm you are comfortable with the skill creating local CSV schedule artifacts and with scheduling_guidance influencing task order and start time. Run it with a dedicated output directory and avoid placing unrelated sensitive data in the request JSON.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
Findings (4)

Tp4

High
Category
MCP Tool Poisoning
Confidence
96% confidence
Finding

The skill is presented as a narrow schedule builder, but the description says it runs a bundled Python operation from a package directory, dispatches by configuration, and writes artifacts to a user-supplied output directory. This broader executor behavior creates a trust boundary mismatch: users and orchestrators may invoke it expecting simple formatting logic while it actually performs package-driven execution and filesystem writes.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
98% confidence
Finding

The skill is presented as a narrow schedule builder, but the description says it runs a bundled Python operation from a package directory, dispatches by configuration, and writes artifacts to a user-supplied output directory. This broader executor behavior creates a trust boundary mismatch: users and orchestrators may invoke it expecting simple formatting logic while it actually performs package-driven execution and filesystem writes.

Content

No source excerpt is available for this finding.

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
76% confidence
Finding

The skill declares no explicit tool scope or permissions, yet the packaged operation is described as reading local input files and static analysis detected network capability. That mismatch weakens containment and makes it harder for a caller or platform to enforce least privilege, increasing the risk of unintended file access or unauthorized outbound communication if the implementation is broader than the markdown claims.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
90% confidence
Finding

The input schema accepts multiple loosely constrained shapes, including raw strings, nested objects, and objects with additionalProperties enabled throughout. This broad acceptance increases the attack surface for prompt/input injection, ambiguous parsing, and unintended downstream behavior because untrusted fields can be supplied without validation or scope restrictions.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.