Back to skill

Security audit

ArifOS Sense

Security checks for vulnerabilities and agentic risk

Overview

This skill is a governance tool, but it gives itself broad control over the agent and creates persistent cross-session decision logs with unclear user control.

Install only if this is specifically for Arif's own arifOS workflow and you want a strict governance layer that can pause actions and keep persistent audit logs. Other users should review or modify it first so authority belongs to the authenticated user, activation is explicit, and any memory logging is opt-in, scoped, redactable, and deletable.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Findings (2)

T01 · Skill Instruction Hijacking

Error
Location
SKILL.md:38
Finding

Non-Negotiable Governance Instructions Hijack Agent Control and Approval Authority

Content
View full analysis
Remediation
View remediation

T02 · Agent Memory Poisoning

Error
Location
SKILL.md:47
Finding

Persistent Governance Ledger Can Poison Agent State Across Sessions

Content
View full analysis
Remediation
View remediation
Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (3)

Vague Triggers

High
Category
Not specified by scanner
Confidence
95% confidence
Finding

The trigger list in metadata is extremely broad and includes common words like "evaluate," "hold," and "is this safe," which can cause the governance skill to activate in many unrelated conversations. In an agent system, this kind of over-triggering can unpredictably override other skills, block normal actions, or inject governance behavior into benign tasks, creating denial-of-service and control-flow manipulation risk.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

The "When to Trigger This Skill" section uses subjective conditions such as requests involving external systems, irreversible actions, or the appearance of words like "evaluate" and "HOLD" without precise scoping. Ambiguous activation criteria make the skill hard to predict and can let adversarial prompts intentionally invoke or suppress the governance layer, weakening reliability and potentially interfering with other safety or task-routing mechanisms.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
80% confidence
Finding

The file includes Indonesian terms such as "Amanah," "Hidayat," and the mixed-language phrase "From weakest to strongest约束" as core operating vocabulary, but it does not state that the user opted into this language or provide an alternative. This can violate a language/locale policy when a skill imposes terminology the user may not understand.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.