Back to skill

Security audit

Knowledge Gaps

Security checks for vulnerabilities and agentic risk

Overview

The skill has a coherent purpose, but it asks the agent to run a shell command using user question text and store a persistent knowledge-gap log without enough safeguards.

Review before installing. This skill should only be used if the logger is present and audited, the agent invokes it without shell interpolation, and users understand that unanswered questions may be stored for later review. Add consent, redaction, retention limits, and safer structured logging before broad use.

Vulnerability Patterns
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (1)

T09 · Insecure Skill Coding Practices

Error
Location
SKILL.md:10
Finding

Shell Command Injection Through User-Controlled Knowledge-Gap Text

Content
View full analysis
Remediation
View remediation
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (2)

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The trigger condition is broad: any time Hans 'cannot answer' or says phrases like 'I don't know,' the skill instructs the agent to execute a logging command. Ambiguous activation increases the chance the skill runs in unintended contexts, causing unnecessary command execution and logging of user content that may be sensitive or unrelated to a true knowledge-gap event.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
98% confidence
Finding

The skill mandates a fixed German-language response regardless of the user's language or preferences. While not a direct security exploit, it can mislead users, reduce transparency, and create unsafe UX behavior by forcing a canned confirmation message after an external action without ensuring language appropriateness or informed consent.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.