Back to skill

Security audit

Warranty & Returns Management

Security checks for vulnerabilities and agentic risk

Overview

This is a plain-text warranty and returns management guidance skill with no executable code, persistence, credential access, or hidden behavior.

Installers should understand this skill as business operations guidance, not legal advice. Review any generated warranty or compliance language with qualified counsel before relying on it in customer-facing terms.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (1)

Vague Triggers

Medium
Confidence
92% confidence
Finding
The phrase "ask your agent to help with warranty policy design, returns optimization, or compliance audits" describes activation in very general terms and does not provide specific trigger phrases, scope boundaries, or negative examples. Because this is a README markdown file, that kind of broad invocation guidance can lead to unintended activation from ordinary domain-related requests.

Static analysis

No suspicious patterns detected.