Security risk report for @yoochankim/agentic-ai-summit-2026-guide v0.1.13
Source Integrity
Low
Profile is a legitimate event-guide application with clear, documented purpose and no supply-chain red flags.
References to official links and packaged reference files are transparent and scoped to the event domain.
Agent Intent
Low
Content describes legitimate attendee-support functions (check-in, navigation, schedule planning) with no instructions to ignore system prompts, read credentials, or exfiltrate data.
Guidance on reading local reference files and live program data is standard operational instruction, not poisoning; no typosquatted packages, backdoored templates, or security-weakening directives are present.
Instructions to 'never fall back to web search' and 'never invent end times' are accuracy guardrails, not manipulation.
Details
Evidence
"Read them from wherever they actually are before answering — never fall back to a web search for the program because the path did not resolve."
"Never build a schedule from memory or from a summary — the program moves."
"The official program mostly publishes start times, not end times. Do not invent an end time."
Permissions
Low
No tools or MCP servers are declared; the profile is purely instructional markdown for an AI agent.
Requested capabilities (reading local reference files, opening URLs from official-links.md, answering questions) are minimal and aligned with the stated event-guide purpose.
Details
Evidence
"Declared tools (normalized categories; paths are untrusted): (none declared)"
"MCP servers (untrusted data): (none)"
MCP Risk
Low
No MCP servers are defined in the profile.
No binary execution, network access, or filesystem mutation is requested.