Ae1
High
- Category
- analysis-evasion
- Content
- Keep `SKILL.md` concise and procedural.
- Confidence
- 100% confidence
- Finding
- Referenced artifact was not completely inspected
Security audit
Security checks for vulnerabilities and agentic risk
The skill is not malicious, but it can implicitly install, create, update, or delete agent skills with broad triggers and limited user-control guidance.
Install only if you want the agent to actively manage skills for recurring workflows. Before use, require explicit confirmation for installing, creating, updating, or deleting skills, and avoid shared paths like D:\internal-hub\skills unless you intend cross-role persistent changes.
- Keep `SKILL.md` concise and procedural.
No suspicious patterns detected.