Back to skill

Security audit

social-org-research

Security checks for vulnerabilities and agentic risk

Overview

The skill is mostly a coherent research prompt, but it asks the agent to persistently update the installed skill after each project without clear user approval.

Review or remove the maintenance notes before installing if you do not want an agent to edit the installed skill over time. Also treat the uninstall command carefully, since it permanently deletes the skill directory; use a confirmed or interactive removal step instead.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Vulnerability Patterns
  • Tool MisuseTool Parameter Abuse, Chaining Abuse, Unsafe Defaults
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
Findings (9)

Tool Parameter Abuse

High
Category
Tool Misuse
Confidence
95% confidence
Finding

The command rm -rf ~/.hermes/skills/social-org-research is a forceful recursive deletion instruction in end-user documentation. Even with a constrained path, such commands are risky because users may execute them without scrutiny, potentially against the wrong path, through copy/paste mistakes, shell expansion issues, or from privileged contexts.

Content

Scanner excerpt · INSTALLATION.md (reported line 70)May include surrounding context.

Uninstall

text
rm -rf ~/.hermes/skills/social-org-research

Tool Parameter Abuse

High
Category
Tool Misuse
Confidence
95% confidence
Finding

The command rm -rf ~/.hermes/skills/social-org-research is a forceful recursive deletion instruction in end-user documentation. Even with a constrained path, such commands are risky because users may execute them without scrutiny, potentially against the wrong path, through copy/paste mistakes, shell expansion issues, or from privileged contexts.

Content

Scanner excerpt · INSTALLATION.md (reported line 70)May include surrounding context.

Uninstall

text
rm -rf ~/.hermes/skills/social-org-research

Skill Enumeration

Medium
Category
Agent Snooping
Confidence
80% confidence
Finding

Skill enumerates or reads other installed skills. Access to other skills' SKILL.md files or the skills directory reveals prompt instructions, capabilities, and secrets that should be invisible to peer skills.

Content

Scanner excerpt · INSTALLATION.md (reported line 14)May include surrounding context.

If you already have this repo cloned to ~/.hermes/skills/social-org-research/, you're done — Hermes auto-discovers skill folders.

text
ls ~/.hermes/skills/social-org-research/SKILL.md

Inside any Hermes conversation, /skills list should show "social-org-research".

Skill Enumeration

Medium
Category
Agent Snooping
Confidence
80% confidence
Finding

Skill enumerates or reads other installed skills. Access to other skills' SKILL.md files or the skills directory reveals prompt instructions, capabilities, and secrets that should be invisible to peer skills.

Content

Scanner excerpt · INSTALLATION.md (reported line 61)May include surrounding context.

If you already have this repo cloned to ~/.hermes/skills/social-org-research/, you're done — Hermes auto-discovers skill folders.

text
ls ~/.hermes/skills/social-org-research/SKILL.md

Inside any Hermes conversation, /skills list should show "social-org-research".

Skill Enumeration

Medium
Category
Agent Snooping
Confidence
80% confidence
Finding

Skill enumerates or reads other installed skills. Access to other skills' SKILL.md files or the skills directory reveals prompt instructions, capabilities, and secrets that should be invisible to peer skills.

Content

Scanner excerpt · INSTALLATION.md (reported line 62)May include surrounding context.

If you already have this repo cloned to ~/.hermes/skills/social-org-research/, you're done — Hermes auto-discovers skill folders.

text
ls ~/.hermes/skills/social-org-research/SKILL.md

Inside any Hermes conversation, /skills list should show "social-org-research".

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

The uninstall step uses a recursive force deletion command without any warning, confirmation, or safety guidance. While the target path is relatively specific, destructive shell commands in installation docs are dangerous because users may run them blindly, with elevated privileges, or after accidental path expansion/editing mistakes.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

The trigger phrases are broad enough to match ordinary research or due-diligence requests, which can cause the agent to invoke this skill when a more appropriate skill should handle the task. Because this skill also pushes specific output tooling and workflow requirements, over-triggering can misroute user intent, expand scope unnecessarily, and increase the chance of unsafe or unintended downstream actions.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

The case study embeds example user prompts such as "Help me deep-research BottleDream" and follow-up asks that are phrased like ordinary user requests, with no visible scoping or exclusion boundaries. In skills that may be auto-selected or triggered from natural-language matches, broad example phrasing can cause unintended activation on unrelated but common research requests, leading to overbroad behavior, unnecessary data gathering, or execution of downstream workflow steps such as report/PDF generation.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
93% confidence
Finding

Line L052 explicitly says the package is "English-only," which is a natural-language locale restriction. The file does not offer a user language choice or opt-in, so this conflicts with the policy requirement to avoid forcing a specific language unless clearly optional or justified.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.