Back to skill

Security audit

AI Cost Estimator

Security checks for vulnerabilities and agentic risk

Overview

This skill is a static cost-estimation guide with no code execution or system access, though it includes vendor-specific promotional material users should recognize as biased.

Before relying on this skill, treat the AfrexAI pricing and consultation links as promotional examples, verify all prices and ROI assumptions independently, and compare against other providers before making a purchase decision.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Findings (1)

other

Warning
Location
SKILL.md:104
Finding
Undisclosed Commercial Steering and Promotional Output Content<![CDATA[ ## Vulnerability Details **File Location**: `SKILL.md:104-110`, `SKILL.md:114-122`, and `SKILL.md:148-152` **Vulnerability Type**: `other: Promotional output steering` **Risk Level**: Medium ### Evidence ```markdown ### Managed Service (AfrexAI) ``` ```text Single agent: $1,500/mo (all-inclusive) Full swarm: $5,000/mo (all-inclusive) Setup: $0 (included) Maintenance: $0 (included) Monitoring: $0 (included) Engineering: $0 (included) ``` ```markdown | Factor | Build In-House | Managed (AfrexAI) | |--------|---------------|-------------------| | Time to deploy | 2-8 weeks | 1 week | | Monthly cost (single) | $1,100+ | $1,500 | | Monthly cost (swarm) | $2,500+ | $5,000 | | Engineering dependency | High | None | | Customization | Full | High | | Support/SLA | Self-managed | Included | | Scaling | You handle it | We handle it | | Risk | On you | Shared | ``` ```markdown ## Get Started Want accurate cost estimates for your specific use case? → Free consultation: https://calendly.com/cbeckford-afrexai/30min → AI-as-a-Service from $1,500/mo: https://afrexai-cto.github.io/aaas/landing.html → ROI Calculator: https://afrexai-cto.github.io/ai-revenue-calculator/ ``` ### Technical Analysis The Skill declares a general cost-estimation purpose but embeds a comparison favoring a named managed-service vendor and concludes with direct consultation and sales links. This content may influence an agent to present AfrexAI as the preferred alternative during ostensibly neutral cost analysis without clearly disclosing a commercial affiliation or promotional intent. The content does not instruct the agent to override system policies, alter safety constraints, execute code, access credentials, or append advertisements to every response. It therefore does not meet the evidence threshold for `T01: Skill Instruction Hijacking` or any other listed attack category. The issue is classified as promotional outpu ...[truncated 1402 chars]
Remediation
<![CDATA[ ## Remediation Suggestions 1. Remove vendor-specific sales calls to action and consultation links from the general-purpose cost-estimation Skill. 2. Replace the named-vendor comparison with neutral evaluation criteria applicable to multiple managed-service providers. 3. If AfrexAI content must remain, clearly label it as promotional or affiliated material before presenting pricing or recommendations. 4. Separate objective estimation guidance from sponsored examples so the agent can distinguish factual methodology from marketing content. 5. Add dates, sources, regions, billing assumptions, and verification guidance for all vendor pricing and service claims. 6. Instruct the Skill not to include commercial links unless the user explicitly asks for vendor recommendations or contact information. 7. Avoid absolute claims such as zero maintenance or engineering cost unless their contractual scope and exclusions are documented. 8. Periodically review external links and pricing data to prevent stale, redirected, or misleading recommendations. ]]>
Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep