Back to skill

Security audit

Catalyst Design

Security checks across malware telemetry and agentic risk

Overview

This skill is a catalyst-design reference and proposal helper with no executable code, and its only write behavior is a clearly disclosed, user-triggered update to its own reference files.

Installers should understand that the skill is normally a read-only catalyst design assistant. Only ask it to update or remember methodology if you want it to change its own bundled reference files; otherwise it should only generate advice and proposals from existing or supplied evidence.

Vulnerability Patterns
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (1)

Intent-Code Divergence

Medium
Confidence
83% confidence
Finding
The file states that updates occur only when the user explicitly opts in and that the skill is read-only by default, but later sections introduce periodic review and evidence-driven update behavior that can be interpreted as autonomous maintenance triggers. In an agent setting, this ambiguity can enable unintended writes to persistent methodology files without fresh per-conversation consent, weakening user control and audit expectations.

VirusTotal

62/62 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.