Back to skill

Security audit

delegation-core

Security checks for vulnerabilities and agentic risk

Overview

This is a documentation-only delegation framework for using external LLMs, with privacy and scoping caveats users should read before sending code or files out of their environment.

Install only if you intend to delegate selected work to external LLM services. Before using it, confirm that the files, prompts, account metadata, and logs you provide are allowed to leave your local environment, redact secrets and regulated data, and prefer local handling for auth, crypto, secret scanning, or other sensitive tasks.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Memory PoisoningPersistent Context Injection, Context Window Stuffing, Memory Manipulation
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
Findings (6)

Context Window Stuffing

Medium
Category
Memory Poisoning
Confidence
80% confidence
Finding

Skill attempts to fill the context window with filler content, displacing legitimate instructions and safety constraints. This can degrade agent performance or bypass safety boundaries.

Content

Scanner excerpt · SKILL.md (reported line 12)May include surrounding context.

md
- qwen
  - task-management
  - quality-control
  - tasks exceed context window or need cheaper processing
metadata: {"openclaw": {"homepage": "https://github.com/athola/claude-night-market/tree/master/plugins/conjure", "emoji": "\ud83e\udd9e", "requires": {"config": ["night-market.leyline:quota-management", "night-market.leyline:usage-logging", "night-market.leyline:service-registry", "night-market.leyline:error-patterns", "night-market.leyline:authentication-patterns"]}}}
source: claude-night-market
source_plugin: conjure

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

The trigger set is broad and includes generic concepts like 'delegation', 'external-llm', and a full natural-language phrase about tasks exceeding context windows. This can cause the skill to activate in situations where the user did not explicitly intend to send work to external services, increasing the chance of accidental data exposure or unsafe delegation.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
98% confidence
Finding

The skill describes delegating tasks to Gemini or Qwen but does not prominently warn that task context may be transmitted to third-party LLM providers. Users may therefore delegate sensitive code, credentials, internal documents, or regulated data without informed consent, creating confidentiality and compliance risks.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The delegation guidance tells operators to include files and context in external LLM requests, but it does not require an explicit user warning or consent step before transmitting potentially sensitive material to third-party services. In a delegation framework, this omission can lead to inadvertent disclosure of source code, secrets, internal documents, or regulated data because users may follow the documented workflow as-is.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

This markdown file instructs users to set account-related environment variables, including a user email address and organization/account identifiers, but does not warn that these values are sensitive or should be handled carefully. Under the markdown-file criteria for missing user warnings, documentation should disclose privacy or system-integrity implications when directing users to manage sensitive data.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

Low
Category
Not specified by scanner
Confidence
89% confidence
Finding

The parent skill manifest says delegation is to Gemini or Qwen, and this file's description is about cost optimization for external LLM delegation. However, the model-selection section recommends unrelated model names such as haiku, sonnet, and opus, which broadens behavior guidance beyond the declared Gemini/Qwen scope.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.