Back to skill

Security audit

Cross-Pollination Engine

Security checks for vulnerabilities and agentic risk

Overview

This is a non-executable brainstorming skill with one childcare privacy caution but no hidden code, persistence, credential use, or automatic actions.

Installers should treat this as a brainstorming aid, not implementation guidance. For any childcare or other sensitive-data idea it produces, require verified consent, secure channels, recipient controls, data minimization, and legal/privacy review before building or sending updates.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (2)

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
97% confidence
Finding

The skill description includes many broad and generic trigger phrases such as "think outside the box," "different industry," and "what can we learn from," which can match common user language outside the intended use case. This can cause unintended invocation of the skill, leading to irrelevant guidance, context hijacking within an agent pipeline, or interference with more appropriate skills.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

The example recommends proactive photo and text updates about a child from a named caregiver without mentioning parental consent, secure delivery, or limits on sharing personally identifiable information. In a childcare context, normalizing this pattern can lead implementers to build features that expose sensitive child data or send updates to unauthorized recipients, creating privacy and safeguarding risks.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.