Back to skill

Security audit

NERRA Token Strategist

Security checks for vulnerabilities and agentic risk

Overview

This is a prompt-only skill for generating Solana meme-token branding and X marketing copy, with no evidence of hidden code execution, data access, persistence, or credential use.

Install only if you want assistance producing speculative meme-token launch and X promotional content. Review generated buy amounts and marketing copy carefully before using them publicly, especially for financial, platform-policy, or market-manipulation risk.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (2)

Vague Triggers

Medium
Confidence
93% confidence
Finding
The trigger condition is underspecified: 'When given a short idea' does not clearly define scope, inputs, or guardrails for when this skill should activate. In an agent environment, ambiguous activation can cause the skill to run on loosely related prompts and generate manipulative token-promotion content outside intended contexts, increasing the chance of misuse.

Natural-Language Policy Violations

Low
Confidence
80% confidence
Finding
The file hard-codes output for 'X (Twitter) engagement' as part of the required behavior, which imposes a specific platform context without offering any user opt-in or alternative. Under the policy, fixed language/locale-style constraints should be optional or clearly justified.

Static analysis

No suspicious patterns detected.