Back to skill

Security audit

recon

Security checks for vulnerabilities and agentic risk

Overview

This skill is a planning checkpoint that reads project context and pauses for confirmation before work, with no evidence of hidden execution, persistence, or data exfiltration.

Install this if you want the agent to pause and produce a reconnaissance report before larger or riskier coding work. Expect it to read relevant repository files and slow down some workflows because its trigger conditions are intentionally broad.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Vulnerability Patterns
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
Findings (2)

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
97% confidence
Finding

The skill says it activates on 'ANY' of several broad conditions such as touching more than one file, involving data processing, or being described as 'big', 'long', or 'risky'. These conditions lack clear scope boundaries or exclusions, so the skill could trigger for a very large portion of normal work rather than a narrowly defined context.

Content

No source excerpt is available for this finding.

Unrestricted Tool Access

Medium
Category
Excessive Agency
Confidence
80% confidence
Finding

Skill grants unrestricted tool access without appropriate constraints. An agent with unfettered tool access can perform arbitrary actions including file modification, network requests, and code execution.

Content

Scanner excerpt · SKILL.md (reported line 99)May include surrounding context.

md
### 5. Stop

Do not write any code. Do not run any command beyond inspection. Do not make a plan beyond the report. Wait for the user.

The purpose of this skill is to prevent wasted effort, not to complete work. Stopping is the job.

Static analysis

No suspicious patterns detected.