Back to skill

Security audit

Software Concept Architect · PRD — Turn Models into Traceable Specs

Security checks for vulnerabilities and agentic risk

Overview

This skill is a documentation/transcription helper that reads project context and writes PRD/spec files, with no hidden execution, credential handling, or persistence beyond the requested documents.

Install this if you want an explicitly invoked helper for turning a confirmed concept model into repository documentation. Review the generated PRD/spec edits like any documentation change, especially because the skill may update existing docs to keep indexes and links consistent.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Findings (1)

Whitespace Padding

Medium
Category
Prompt Injection
Confidence
70% confidence
Finding

Large whitespace padding was detected (a block of blank lines or a long run of spaces). This can push injected instructions below or to the right of the visible area so a human reviewer never sees them while the agent still reads them. Manual review of the hidden content is recommended.

Content

Scanner excerpt · references/templates.md (reported line 6)May include surrounding context.

md
Read `spec-format.md` first; this file governs where a confirmed model is persisted, not its syntax.
See `example-reserving.md` for a traced example.

| Content                                          | Authoritative location                                                              | Requirement                                                                                                            |
| ------------------------------------------------ | ----------------------------------------------------------------------------------- | ---------------------------------------------------------------------------------------------------------------------- |
| Application purpose, scenarios, misfits          | overall PRD                                                                         | preserve concept/sync basis and cross-concept assumptions; mark missing purpose open                                   |
| One concept                                      | CONCEPT.md beside its module; stage under `docs/prd/concepts/` before modules exist | transcribe four core sections, declared queries, and notes; concrete types belong in SYNCS                             |

Static analysis

No suspicious patterns detected.