Back to skill

Security audit

Performance Review Engine

Security checks for vulnerabilities and agentic risk

Overview

This is a disclosed performance-review template skill with sensitive HR use cases, but no hidden execution, data access, persistence, or exfiltration behavior was found.

Install only for authorized HR or management use. Treat all review notes, peer feedback, promotion status, flight-risk labels, and PIP information as confidential employment data, and use human review plus legal or HR policy checks before relying on outputs for compensation, promotion, discipline, or termination decisions.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Vulnerability Patterns
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
Findings (4)

Missing User Warnings

Medium
Confidence
93% confidence
Finding
The README explicitly promotes collecting, anonymizing, and synthesizing 360° feedback, which involves highly sensitive employee data and subjective assessments. Presenting this capability without privacy, consent, retention, access-control, or re-identification warnings can lead users to deploy the skill for HR processing in ways that expose confidential personnel information or create compliance risk.

Missing User Warnings

Medium
Confidence
93% confidence
Finding
The README markets weighted performance scoring and team dashboards for personnel evaluation without warning that these outputs may influence consequential employment decisions such as ratings, promotion, compensation, or termination. In an HR context, omission of fairness, validation, transparency, and human-review safeguards makes the skill more dangerous because users may over-trust AI-generated scores for high-impact decisions involving sensitive employee data.

Missing User Warnings

Medium
Confidence
88% confidence
Finding
This section instructs the agent to collect, aggregate, and summarize identifiable peer and employee performance feedback while promising anonymization, but it does not include safeguards for consent, access control, data minimization, storage/retention, or limits on sharing. In an HR context, this is sensitive personnel data, and mishandling it can expose confidential evaluations, create workplace harm, and trigger privacy or employment compliance issues.

Missing User Warnings

Medium
Confidence
92% confidence
Finding
The analytics section encourages generating dashboards containing named promotion candidates, flight risks, and PIP/coaching status without any warning that this is highly sensitive HR data requiring strict confidentiality. If exposed or broadly shared, these labels could cause employee harm, retaliation concerns, morale issues, and legal/compliance risk due to profiling and unauthorized disclosure.

Static analysis

No suspicious patterns detected.