Back to skill

Security audit

Press

Security checks for vulnerabilities and agentic risk

Overview

This is a markdown-only public relations guidance skill with a somewhat broad activation description but no hidden execution, data access, persistence, or privileged behavior.

This skill is reasonable to install for press releases, media pitching, PR strategy, and crisis response drafting. Be aware it may activate for general public-communication requests where a narrower writing or marketing skill could be more appropriate, so review generated external statements before using them publicly.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (1)

Vague Triggers

Medium
Confidence
95% confidence
Finding
The manifest description contains very broad trigger phrases such as 'communicate with the public at scale' and 'any scenario involving earned media, reputation management, or public communication,' which can cause the skill to activate for many general writing, messaging, or advisory requests outside narrow PR tasks. Overbroad routing can misinvoke this skill in unrelated contexts, leading to inappropriate handling, reduced least-privilege behavior, and possible interference with safer or more specialized skills.

Static analysis

No suspicious patterns detected.