Back to skill

Security audit

JSON Transformer

Security checks for vulnerabilities and agentic risk

Overview

The skill is markdown-only and shows no code execution or persistence, but its JSON-transformer purpose is mixed with unrelated GNN/Transformer learning content and triggers.

Review this skill carefully before installing. It does not appear to execute code or access private data, but it is mislabeled and cluttered with unrelated learning content, so it may activate for the wrong requests or give irrelevant guidance for JSON work.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
Findings (4)

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The trigger phrases are broad and map to very common JSON-related requests, increasing the chance this skill will activate in situations where a more specific or safer skill should handle the task. Because the skill content is already semantically inconsistent, overbroad activation materially raises the risk of inappropriate behavior or prompt/skill hijacking through routine user language.

Content

No source excerpt is available for this finding.

Intent-Code Divergence

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The embedded sub-skill content clearly conflicts with the declared purpose of a JSON transformation skill by introducing unrelated GNN/trajectory-prediction material. This kind of semantic drift can cause the agent to invoke the wrong instructions for common JSON tasks, leading to misrouting, degraded reliability, and potentially unsafe behavior if unrelated capabilities are executed under a trusted skill name.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
90% confidence
Finding

The secondary trigger text uses vague help-seeking language tied to the unrelated embedded sub-skill, which can cause accidental invocation from ambiguous user requests. In the context of a mislabeled skill, ambiguous activation broadens the attack surface for confusion, unintended routing, and execution of instructions outside the user's actual task.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
78% confidence
Finding

The file presents user-facing descriptions in both English and Chinese, and the body content is primarily Chinese, but it does not state any user-selectable language preference or opt-in behavior. This can create a locale/language policy issue if the skill defaults to a language the user did not request.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.