Back to skill

Security audit

Transformer Optimize E72719

Security checks for vulnerabilities and agentic risk

Overview

The skill is not malicious, but its stated MATLAB forecasting purpose is mixed with unrelated video-learning content and broad triggers that could activate it for the wrong requests.

Review this skill before installing. It appears low-risk to the local system, but it is poorly scoped and may cause the agent to answer unrelated MATLAB, Transformer, DSPy, or Andrew Ng requests using mixed source material. Install only if you are comfortable curating or narrowing the triggers and references.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
Findings (5)

Description-Behavior Mismatch

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

The skill metadata and description claim a MATLAB Transformer time-series forecasting capability, but the body is mostly a loose aggregation of unrelated video references, including DSPy/agent-app content and non-relevant media. This mismatch can cause the agent to activate under false pretenses and deliver irrelevant or unsafe guidance, undermining predictability and trust in skill selection.

Content

No source excerpt is available for this finding.

Intent-Code Divergence

Medium
Category
Not specified by scanner
Confidence
89% confidence
Finding

The inline documentation asserts one learning objective, but the cited sources contradict it by including unrelated optimization, entertainment, and DSPy agent-building material. Contradictory provenance increases the chance of poisoned or low-integrity skill behavior, where users receive advice sourced from irrelevant material while believing it is domain-specific.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The trigger example around this line is overly broad, making it likely that unrelated user requests will invoke the skill. In an agent system, ambiguous activation can route users into the wrong capability, producing misleading outputs and increasing the chance that irrelevant embedded content influences responses.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The trigger phrase '吴恩达' is extremely broad and likely to collide with many unrelated requests about Andrew Ng rather than this specific skill. Because the merged section also references agent-app optimization content, accidental activation could expose users to behavior outside the stated MATLAB forecasting scope.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The merged skill section uses an overly broad activation condition for 'transformer-optimize-e72719相关帮助', which can match many generic help requests. In context, the skill already contains mixed domains, so broad triggering makes accidental invocation more dangerous by amplifying the content-integrity problem.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.