Back to skill

Security audit

Content Gap Analysis

Security checks for vulnerabilities and agentic risk

Overview

This content gap skill is mostly purpose-aligned, but it asks agents to write durable shared memory even though its manifest only declares inline output and state-read capabilities.

Review this before installing if you rely on capability declarations or shared agent memory. It should be acceptable only if you are comfortable with the skill saving content strategy conclusions into persistent memory; otherwise require inline-only output or explicit approval before any memory updates.

Vulnerability Patterns
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (1)

T05 · Unauthorized Access and Privilege Escalation

Warning
Location
SKILL.md:32
Finding

Persistent Memory Writes Exceed the Declared Capability Boundary

Content
View full analysis
.md`; promote durable gap priorities and competitor facts to `memory/hot-cache.md`. See [Skill Contract](../../../references/skill-contract.md) §Save Results Template. ``` `distribution-manifest.json:2-7`: ```json "capabilities": [ "inline-delivery", "canonical-state-read" ], "capability_ceiling": "lite", ``` ### Technical Analysis The distribution manifest declares only inline delivery and canonical state-read capabilities. However, the Skill instructions explicitly direct the agent to write analysis results into `memory/research/`, `memory/hot-cache.md`, and `memory/open-loops.md`. This creates a least-privilege and capability-declaration mismatch: persistent state modification is required by the Skill but is not represented by the declared capability set. The writes are also not conditioned on explicit user approval. The data selected for persistence may include competitor facts, keyword priorities, and pending strategic decisions derived from externally retrieved website content. Although no direct instruction-hijacking payload was identified in the reviewed files, untrusted or inaccurate competitor content could ...[truncated 1497 chars]
Remediation
View remediation
Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep

Static analysis

No suspicious patterns detected.