Back to skill

Security audit

Skill Auditor

Security checks for vulnerabilities and agentic risk

Overview

This is a real skill-auditing guide, but it gives the agent overly broad authority to read referenced local files, fetch remote content, and force response formatting.

Review before installing. This skill should be run only in a sandboxed, read-only copy of the submitted skill bundle, with out-of-root file reads and remote fetching disabled unless explicitly approved per target. Its triggers and final-output rules should also be narrowed so it does not take over unrelated skill workflows or structured responses.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
Findings (3)

T01 · Skill Instruction Hijacking

Error
Location
SKILL.md:26
Finding

Broad Trigger Rules and Mandatory Output Overrides Can Hijack Agent Behavior

Content
View full analysis

Vulnerability Details

File Location: SKILL.md, lines 26-43 and 439-448
Vulnerability Type: T01: Skill Instruction Hijacking
Risk Level: High

Relevant Snippets:

markdown
===== Triggering keywords (natural language, Chinese or English) =====
add skill, install skill, create skill, creating a new skill,
write a skill, scaffold a skill, new skill, register skill, import skill,
update skill, modify skill, bring in skill, hook up skill,
audit skill, scan skill, check skill safety, analyze skill, inspect skill,
verify skill, skill security, skill supply chain,
这个 skill 安全吗, skill 安全扫描, 检查 skill 安全, 新增 skill,
添加 skill, 安装 skill, 创建 skill, 引入 skill, 更新 skill, 写一个 skill,
接入 skill。
markdown
## Language Detection Rule — EXECUTE BEFORE ANYTHING ELSE

Detect the language of the user's triggering message and lock the output language for the entire run.
markdown
The **only mandatory final emission is a single Chinese one-liner** that maps directly from the verdict tier.
markdown
- The final line is **always Chinese**, regardless of the run's detected output language.
- The line must be the **last non-empty line** of the entire output.
- Emit **exactly one** final line.

Technical Analysis

The Skill defines broad natural-language activation conditions and uses priority-style directives such as “EXECUTE BEFORE ANYTHING ELSE.” Once activated, it attempts to control the language and final structure of the agent's response, including requiring a Chinese final line even when the user requested another language.

These requirements are not necessary to perform static security analysis. They affect session-level response behavior rather than only defining the security checks the Skill should perform. If treated as authoritative when the Skill is loaded, the instructions can conflict with the current user's requested language, output schema, or downstream automation req ...[truncated 896 chars]

Remediation
View remediation

Remediation Suggestions

  • Remove priority-style wording such as “EXECUTE BEFORE ANYTHING ELSE.”
  • Limit activation to an explicit user request to audit a Skill rather than broad keywords.
  • State that system and user instructions always take precedence over Skill formatting preferences.
  • Remove the mandatory Chinese final line and use the language explicitly requested by the user.
  • Make the output template optional or configurable.
  • Ensure the Skill's instructions are scoped exclusively to audit methodology and do not attempt to control unrelated session behavior.

T05 · Unauthorized Access and Privilege Escalation

Error
Location
SKILL.md:344
Finding

Out-of-Root Reference Resolution Can Expose Arbitrary Local Files

Content
View full analysis

Vulnerability Details

File Location: SKILL.md, lines 344-347
Vulnerability Type: T05: Unauthorized Access and Privilege Escalation
Risk Level: High

Relevant Snippet:

markdown
2. **Locally referenced resources.** Resolve relative-path references that appear in `SKILL.md` and in scripts (frontmatter, code blocks, Markdown links, arguments to bash / python / node invocations, etc.) and pull the referenced files into the scan. Their Reachability baseline is set per §5.3. If a referenced file lies outside the skill directory, additionally record an `FS.ReadOutOfScope` or `AGT.CrossSkillWrite` finding as appropriate.

Technical Analysis

The audit procedure directs the agent to resolve references and pull referenced files into the scan even when those files are outside the audited Skill directory. Recording an FS.ReadOutOfScope finding does not prevent the read.

Because the audited Skill is an untrusted input, its Markdown, script arguments, or links can contain path traversal sequences or absolute paths. Resolving those paths without enforcing a canonical-root boundary can cause unrelated user files, workspace files, credentials, or agent configuration to be loaded into the model context.

Reading external files is not required to determine that a Skill attempts to access them. The auditor can safely report the reference without dereferencing it.

Attack Path

  1. An attacker publishes a Skill containing a local reference such as ../../.ssh/id_rsa, ~/.aws/credentials, or an absolute path.
  2. A user asks the auditor to inspect that Skill.
  3. The auditor resolves the attacker-controlled reference according to the documented procedure.
  4. The external file is read and added to the scan context.
  5. Sensitive content becomes exposed to the agent, logs, model provider, or subsequent prompt-processing logic.

Impact Assessment

Exploitation could disclose files readable by the account runn ...[truncated 366 chars]

Remediation
View remediation

Remediation Suggestions

  • Canonicalize every referenced path before access.
  • Enforce that the canonical path remains under the canonical Skill root.
  • Reject absolute paths, home-directory expansion, traversal components, and symbolic links that escape the root.
  • When an out-of-root reference is found, record its literal value as a finding without opening the target.
  • Require explicit, per-file user approval before accessing any external resource.
  • Redact sensitive data and avoid placing raw credentials or private keys into model context or logs.
  • Run the auditor in a filesystem sandbox with access limited to a read-only copy of the submitted Skill.

T09 · Insecure Skill Coding Practices

Warning
Location
SKILL.md:348
Finding

Unrestricted Static Remote Fetch Creates SSRF and Untrusted-Content Ingestion Risk

Content
View full analysis

Vulnerability Details

File Location: SKILL.md, lines 348-350 and 403-406
Vulnerability Type: T09: Insecure Skill Coding Practices
Risk Level: Medium

Relevant Snippets:

markdown
3. **Remote resources.** Patterns such as `curl | sh`, `wget`, `git clone` then `exec`, `pip`/`npm` pointing at non-standard registries, or remote MCP servers trigger `EXE.RemoteFetch` or `AGT.MCPRemoteFetch`. During the audit, a single static fetch is allowed (never executed); on success the content joins the scan, on failure or without authorization the finding's `I` is forced to `≥ 2`.
text
[Step 1] Build scan inventory
  ├─ 1a. Recursively enumerate files and classify by content
  ├─ 1b. Parse references → add local files / register remote-URL findings
  ├─ 1c. Match each outbound URL against §5.1.1 Untrusted-Sink Indicators
  └─ 1d. Attempt a single static fetch of remote resources (success → include; failure → I ≥ 2)

Technical Analysis

The procedure permits the auditor to fetch an arbitrary remote resource supplied by the untrusted Skill. Although the fetched content is not executed, making the request itself can create server-side request forgery behavior if URL schemes, DNS results, redirects, ports, and destination address ranges are not constrained.

A crafted URL could target loopback services, private network systems, link-local cloud metadata endpoints, or redirect from a public host to an internal address. Adding the response to the scan also introduces untrusted remote text into the agent's context, where it may contain prompt-injection instructions or consume excessive resources.

The Skill documents structural sink detection, but it does not establish comprehensive outbound request controls, content-size limits, safe content types, redirect validation, or private-address blocking.

Attack Path

  1. An attacker places a URL in the audited Skill.
  2. The URL points directly to an interna ...[truncated 794 chars]
Remediation
View remediation

Remediation Suggestions

  • Disable remote fetching by default and report remote URLs without contacting them.
  • Require explicit user approval for each destination before a fetch.
  • Allow only HTTPS and reject file, ftp, gopher, data, and other unnecessary schemes.
  • Resolve DNS and block loopback, private, link-local, multicast, reserved, and cloud-metadata address ranges for IPv4 and IPv6.
  • Revalidate the destination after every redirect and DNS resolution.
  • Apply strict connection, read, redirect, and total-duration limits.
  • Enforce response-size and content-type limits.
  • Treat fetched material strictly as untrusted data and isolate it from agent instructions.
  • Use a sandboxed fetch proxy without access to internal networks or ambient credentials.
Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Findings (30)

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 8)May include surrounding context.

md
bundle — `SKILL.md`, every script next to it (`.sh` / `.py` / `.js`,

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 200)May include surrounding context.

md
bundle — `SKILL.md`, every script next to it (`.sh` / `.py` / `.js`,

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 346)May include surrounding context.

md
bundle — `SKILL.md`, every script next to it (`.sh` / `.py` / `.js`,

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 349)May include surrounding context.

md
bundle — `SKILL.md`, every script next to it (`.sh` / `.py` / `.js`,

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 401)May include surrounding context.

md
bundle — `SKILL.md`, every script next to it (`.sh` / `.py` / `.js`,

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 402)May include surrounding context.

md
bundle — `SKILL.md`, every script next to it (`.sh` / `.py` / `.js`,

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 443)May include surrounding context.

md
bundle — `SKILL.md`, every script next to it (`.sh` / `.py` / `.js`,

Self-Modification

High
Category
Rogue Agent
Confidence
85% confidence
Finding

Skill modifies its own code, configuration, or behavior at runtime. Self-modification enables an agent to escalate privileges, disable safety constraints, or install persistent backdoors.

Content

Scanner excerpt · SKILL.md (reported line 26)May include surrounding context.

md
===== Triggering keywords (natural language, Chinese or English) =====
  add skill, install skill, create skill, creating a new skill,
  write a skill, scaffold a skill, new skill, register skill, import skill,
  update skill, modify skill, bring in skill, hook up skill,
  audit skill, scan skill, check skill safety, analyze skill, inspect skill,
  verify skill, skill security, skill supply chain,
  这个 skill 安全吗, skill 安全扫描, 检查 skill 安全, 新增 skill,

Self-Modification

High
Category
Rogue Agent
Confidence
85% confidence
Finding

Skill modifies its own code, configuration, or behavior at runtime. Self-modification enables an agent to escalate privileges, disable safety constraints, or install persistent backdoors.

Content

Scanner excerpt · SKILL.md (reported line 26)May include surrounding context.

md
===== Triggering keywords (natural language, Chinese or English) =====
  add skill, install skill, create skill, creating a new skill,
  write a skill, scaffold a skill, new skill, register skill, import skill,
  update skill, modify skill, bring in skill, hook up skill,
  audit skill, scan skill, check skill safety, analyze skill, inspect skill,
  verify skill, skill security, skill supply chain,
  这个 skill 安全吗, skill 安全扫描, 检查 skill 安全, 新增 skill,

External Script Fetching

High
Category
Supply Chain
Confidence
90% confidence
Finding

Remote code is downloaded and executed. This bypasses code review and could introduce malicious code.

Content

Scanner excerpt · SKILL.md (reported line 86)May include surrounding context.

md
| `EXE.StaticShell` — shell with fully constant arguments | 2 | R, B | transform |
| `EXE.DynamicShell` — variable interpolation / `shell=True` + external input | 4 | R, I, B | sink |
| `EXE.EvalCode` — `eval` / `exec` / `Function()` on strings | 4 | R, I, B | sink |
| `EXE.RemoteFetch` — `curl \| sh` / download-then-exec / fetch-and-run | 4 | I, B | sink |
| `EXE.Subprocess` — constrained subprocess (whitelisted commands) | 2 | R | transform |

#### FS

External Script Fetching

High
Category
Supply Chain
Confidence
90% confidence
Finding

Remote code is downloaded and executed. This bypasses code review and could introduce malicious code.

Content

Scanner excerpt · SKILL.md (reported line 221)May include surrounding context.

md
| `EXE.StaticShell` — shell with fully constant arguments | 2 | R, B | transform |
| `EXE.DynamicShell` — variable interpolation / `shell=True` + external input | 4 | R, I, B | sink |
| `EXE.EvalCode` — `eval` / `exec` / `Function()` on strings | 4 | R, I, B | sink |
| `EXE.RemoteFetch` — `curl \| sh` / download-then-exec / fetch-and-run | 4 | I, B | sink |
| `EXE.Subprocess` — constrained subprocess (whitelisted commands) | 2 | R | transform |

#### FS

Tool Parameter Abuse

High
Category
Tool Misuse
Confidence
80% confidence
Finding

Tool parameters are crafted to achieve unintended or unsafe behavior. Parameter abuse can bypass intended safety checks (e.g. shell=True, --force, dangerous glob patterns).

Content

Scanner excerpt · SKILL.md (reported line 101)May include surrounding context.

md
| `FS.WriteOutOfScope` — write outside declared scope | 3 | I, B | sink |
| `FS.WriteStartup` — write startup hooks / shell rc / autostart / launchd | 4 | R, I | sink |
| `FS.DeleteBroad` — wide deletion / `rm -rf` / wildcard delete / `find ... -delete` | 4 | R, I, B | sink |
| `FS.ChmodDangerous` — chmod 777 / privilege widen / SUID bit | 3 | R, I | transform |

#### NET

Credential Access

High
Category
Privilege Escalation
Confidence
70% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · SKILL.md (reported line 121)May include surrounding context.

md
|----------|--------|----------|-----------|
| `CRED.ReadEnv` — broad read of `os.environ` / `process.env` | 3 | I, B | source |
| `CRED.ReadNamedEnv` — read a single declared environment variable | 1 | — | source |
| `CRED.ReadKeychain` — read Keychain / Credential Manager / libsecret | 4 | I, B | source |
| `CRED.ReadBrowserStore` — read browser cookies / session / password store | 4 | I, B | source |
| `CRED.Hardcoded` — real secret hardcoded in code or config | 3 | R | none |
| `CRED.HardcodedInjected` — hardcoded credential the skill instructs the agent to *inject* into a user system (DB, service, config) | 4 | R, I | sink |

Credential Access

High
Category
Privilege Escalation
Confidence
70% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · SKILL.md (reported line 189)May include surrounding context.

md
|----------|--------|----------|-----------|
| `CRED.ReadEnv` — broad read of `os.environ` / `process.env` | 3 | I, B | source |
| `CRED.ReadNamedEnv` — read a single declared environment variable | 1 | — | source |
| `CRED.ReadKeychain` — read Keychain / Credential Manager / libsecret | 4 | I, B | source |
| `CRED.ReadBrowserStore` — read browser cookies / session / password store | 4 | I, B | source |
| `CRED.Hardcoded` — real secret hardcoded in code or config | 3 | R | none |
| `CRED.HardcodedInjected` — hardcoded credential the skill instructs the agent to *inject* into a user system (DB, service, config) | 4 | R, I | sink |

External Script Fetching

High
Category
Supply Chain
Confidence
90% confidence
Finding

Remote code is downloaded and executed. This bypasses code review and could introduce malicious code.

Content

Scanner excerpt · SKILL.md (reported line 221)May include surrounding context.

md
| T2 | Outbound to an **undeclared** host with a payload built from `os.environ`, file reads, or chat context | **I ≥ 3** |
| T3 | `find ... -delete` / `rm -rf` / wildcard delete that matches **user data file extensions** (`.ics`, `.docx`, `.xlsx`, `.pdf`, `.json`, `.csv`, `.md`, `.txt`, photos, source code) and is invoked by a SKILL.md instruction | **I ≥ 3** |
| T4 | Hardcoded credential (`CRED.Hardcoded`) **plus** an instruction telling the agent to inject it into the user's database / service / config (`CRED.HardcodedInjected`) | **I ≥ 3** |
| T5 | `curl \| sh` / `wget \| bash` / `EXE.RemoteFetch` whose URL is not pinned to a known package registry or a host declared in SKILL.md | **I ≥ 3** |
| T6 | `LLM.ObfuscatedPrompt`, `LLM.UnicodeSmuggling`, base64-encoded directive, or zero-width chars in `description`/`triggers` | **I ≥ 3** |
| T7 | `LLM.PromptOverrideActionable` whose action resolves to T1–T5 | **I ≥ 3** |
| T8 | `AGT.CrossSkillWrite` to a sibling skill directory or to the agent registry | **I ≥ 2** |

External Script Fetching

High
Category
Supply Chain
Confidence
94% confidence
Finding

This section explicitly permits a static fetch of remote resources during audit, which is materially risky for a skill whose core purpose is analysis of local bundles. Allowing network retrieval can expose the agent to hostile remote content, unintended data disclosure, and supply-chain expansion beyond the provided artifact.

Content

Scanner excerpt · SKILL.md (reported line 350)May include surrounding context.

md
1. **Recursive enumeration of the skill directory.** Walk every file (including hidden ones) and classify by content rather than extension. Text-like content is analyzed as script/configuration; non-text content is judged by its location and reference relationships, without any fixed preset conclusion.
2. **Locally referenced resources.** Resolve relative-path references that appear in `SKILL.md` and in scripts (frontmatter, code blocks, Markdown links, arguments to bash / python / node invocations, etc.) and pull the referenced files into the scan. Their Reachability baseline is set per §5.3. If a referenced file lies outside the skill directory, additionally record an `FS.ReadOutOfScope` or `AGT.CrossSkillWrite` finding as appropriate.
3. **Remote resources.** Patterns such as `curl | sh`, `wget`, `git clone` then `exec`, `pip`/`npm` pointing at non-standard registries, or remote MCP servers trigger `EXE.RemoteFetch` or `AGT.MCPRemoteFetch`. During the audit, a single static fetch is allowed (never executed); on success the content joins the scan, on failure or without authorization the finding's `I` is forced to `≥ 2`.

#### 5.1.1 Untrusted-Sink Indicators

Ae4

Medium
Category
analysis-evasion
Confidence
80% confidence
Finding

Suspicious Unicode normalization or mixed-script content

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

Medium
Category
Not specified by scanner
Confidence
88% confidence
Finding

The trigger-routing instructions are unusually broad and can cause the skill to activate for ordinary conversation about skills, expanding its authority beyond a narrowly scoped audit task. Over-broad interception increases the chance of unintended control over agent behavior and can crowd out more appropriate skills or user intent.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

The trigger list is broad enough to match many benign discussions about skills, making the skill prone to unsolicited invocation. In an agent environment, over-triggering can distort task routing, override expected workflows, and increase exposure to prompt-conflict or control-plane abuse.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
98% confidence
Finding

Forcing a Chinese final verdict regardless of user language is not a classic exploit, but it is an unjustified output-control constraint that can impair user comprehension and mask important findings in multilingual environments. Security tooling should not reduce clarity or override user locale without a strong reason.

Content

No source excerpt is available for this finding.

Sudo/Root Execution

Medium
Category
Privilege Escalation
Confidence
80% confidence
Finding

Commands invoke sudo or root privileges. Verify this elevated access is necessary and justified.

Content

Scanner excerpt · SKILL.md (reported line 101)May include surrounding context.

md
| `FS.WriteOutOfScope` — write outside declared scope | 3 | I, B | sink |
| `FS.WriteStartup` — write startup hooks / shell rc / autostart / launchd | 4 | R, I | sink |
| `FS.DeleteBroad` — wide deletion / `rm -rf` / wildcard delete / `find ... -delete` | 4 | R, I, B | sink |
| `FS.ChmodDangerous` — chmod 777 / privilege widen / SUID bit | 3 | R, I | transform |

#### NET

Session Persistence

Medium
Category
Rogue Agent
Confidence
80% confidence
Finding

Skill establishes unauthorized persistence across sessions via cron jobs, startup scripts, or state files. Session persistence allows an attacker to maintain access beyond the current interaction.

Content

Scanner excerpt · SKILL.md (reported line 132)May include surrounding context.

md
| Behavior | C_base | Required | Data-flow |
|----------|--------|----------|-----------|
| `PROC.Spawn` — ordinary child process creation (paired with EXE) | 1 | — | none |
| `PROC.Persist` — cron / launchd / systemd / Run-key install | 4 | R, I | sink |
| `PROC.ToolTamper` — modify / replace system tools, hook package managers | 4 | R, I, B | sink |
| `PROC.CryptoMine` — miner binaries / known mining-pool hosts | 4 | — | sink |
| `PROC.HideSelf` — process masquerade | 3 | I | transform |

Autonomous Decision Making

Medium
Category
Excessive Agency
Confidence
85% confidence
Finding

Skill enables autonomous high-impact decisions without human-in-the-loop verification. Critical operations (destructive commands, financial transactions, data deletion) should require explicit user confirmation.

Content

Scanner excerpt · SKILL.md (reported line 156)May include surrounding context.

md
| `AGT.MCPRemoteFetch` — dynamically fetch tool definitions from a remote MCP server | 3 | I, B | source+sink |
| `AGT.ContextExfil` — exfiltrate data via chat context / tool responses | 3 | I, B | sink |
| `AGT.PrivilegeCreep` — behavior materially exceeds the SKILL.md-declared scope | 3 | I | transform |
| `AGT.ApprovalBypass` — attempts to bypass approval / sandbox / trust boundary | 4 | I | sink |

### 1.3 IntentMarker

Session Persistence

Medium
Category
Rogue Agent
Confidence
80% confidence
Finding

Skill establishes unauthorized persistence across sessions via cron jobs, startup scripts, or state files. Session persistence allows an attacker to maintain access beyond the current interaction.

Content

Scanner excerpt · SKILL.md (reported line 225)May include surrounding context.

md
| T6 | `LLM.ObfuscatedPrompt`, `LLM.UnicodeSmuggling`, base64-encoded directive, or zero-width chars in `description`/`triggers` | **I ≥ 3** |
| T7 | `LLM.PromptOverrideActionable` whose action resolves to T1–T5 | **I ≥ 3** |
| T8 | `AGT.CrossSkillWrite` to a sibling skill directory or to the agent registry | **I ≥ 2** |
| T9 | `PROC.Persist` (cron / launchd / shell-rc) installed by the skill without being declared as the skill's purpose | **I ≥ 2** |
| T10 | `LLM.PromptOverride` directives ("ignore previous", "you are now", "system:") that are not wrapped in a documentation example block | **I ≥ 2** |

**Anti-overshoot guards (must be satisfied to apply a hard trigger):**

Session Persistence

Medium
Category
Rogue Agent
Confidence
80% confidence
Finding

Skill establishes unauthorized persistence across sessions via cron jobs, startup scripts, or state files. Session persistence allows an attacker to maintain access beyond the current interaction.

Content

Scanner excerpt · SKILL.md (reported line 288)May include surrounding context.

md
| M4 | `CRED.HardcodedInjected` (a hardcoded secret the agent is told to push into a user system) | **High** |
| M5 | `EXE.RemoteFetch` from an unpinned, non-declared URL | **High** |
| M6 | `LLM.ObfuscatedPrompt` / `LLM.UnicodeSmuggling` | **High** |
| M7 | `PROC.Persist` (cron / launchd / shell-rc / Run-key) installed without being declared as the skill's purpose | **High** |
| M8 | `AGT.CrossSkillWrite` into another skill's directory or the agent registry | **Medium** |
| M9 | Outbound to an **undeclared** host carrying data sourced from `os.environ`, file reads, or chat context (T2 without an Untrusted-Sink upgrade) | **Medium** |

Static analysis

No suspicious patterns detected.