Back to skill

Security audit

Ru Pack

Security checks for vulnerabilities and agentic risk

Overview

This is a simple Russian-language informational skill pack with no executable code, persistence, external access, or hidden install behavior, though users should treat its legal, medical, and tax help as informational only.

Install only if you want a Russian-language helper for understanding documents and drafting plain-language responses. For medical results, contracts, complaints, and taxes, use it as a first-pass explanation aid and verify important decisions with a qualified doctor, lawyer, accountant, or official source.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
Findings (3)

Tp2

High
Category
MCP Tool Poisoning
Confidence
90% confidence
Finding
Confusable Unicode characters (e.g., Cyrillic or Greek lookalikes of Latin letters) can make a malicious tool name appear identical to a trusted one.

Natural-Language Policy Violations

Medium
Confidence
92% confidence
Finding
The description explicitly targets 'русскоязычных пользователей', and the skill name and examples are entirely Russian-language. Because the file presents a language-specific constraint without an explicit user choice or documented justification, it can violate language/locale policy expectations.

Vague Triggers

Medium
Confidence
95% confidence
Finding
The package says it will 'itself determine the needed skill' from whatever the user writes, but it does not define clear routing boundaries, exclusions, or confirmation behavior. That can cause misclassification of user intent and accidental invocation of sensitive domains like medical, legal, or tax guidance from ambiguous input, increasing the chance of unsafe or inappropriate responses.

Static analysis

No suspicious patterns detected.