Back to skill

Security audit

preflight

Security checks for vulnerabilities and agentic risk

Overview

The skill is coherent but should be reviewed because it tells the agent to automatically run cheap tests that may still touch paid APIs, production systems, or shared data.

Before installing, make sure you are comfortable with the agent automatically running small test operations. Prefer using it only where cheap tests are dry-run, read-only, sandboxed, or explicitly approved before touching paid services, production data, cloud resources, or shared storage.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (2)

Missing User Warnings

High
Category
Not specified by scanner
Confidence
98% confidence
Finding

The skill explicitly instructs the agent to execute a 'cheap version' without asking permission, but the examples include API calls, database operations, and other actions that may still write data, consume money, hit rate limits, or touch production-like systems. In context, this is more dangerous because the skill is intended to run just before expensive or irreversible operations, where even a small unsolicited test can still cause real-world side effects.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The activation conditions are broad and subjective (for example, 'expensive', 'long', or 'risky' and loops over ~100 items), which can cause the skill to trigger in contexts the user did not clearly intend. In an agent setting, ambiguous auto-invocation can alter execution flow and lead to unplanned actions, especially because this skill later directs autonomous execution of a test run.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.