Back to skill

Security audit

Austine Daily Ops

Security checks for vulnerabilities and agentic risk

Overview

This skill is a concise personal daily-operations and travel-planning template with no code, hidden execution, persistence, or credential handling.

Install only if you want this skill to shape responses for Austine-style daily planning and travel logistics. For bookings, payments, vendor messages, reminders, or storing trip details, require explicit user confirmation before taking action.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Vulnerability Patterns
  • System Prompt LeakageDirect Leakage, Indirect Extraction, Tool-Based Exfiltration
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
Findings (2)

Direct Prompt Extraction

High
Category
System Prompt Leakage
Confidence
85% confidence
Finding

Skill contains instructions that could directly expose system prompts, internal rules, or hidden instructions to users or external parties.

Content

Scanner excerpt · SKILL.md (reported line 58)May include surrounding context.

md
- Trigger reminders with time buffer (day-before or earlier for critical items).
- Escalate if no response by cutoff.

## Output Rules
- Bullet-first, concise, high signal.
- No fluff.
- If data is uncertain, say so explicitly.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The skill description is broadly phrased around 'daily execution,' 'status workflows,' and 'trip logistics,' which can cause over-activation for loosely related user requests. In an agent system, this increases the chance the skill is invoked outside a tightly bounded scope, leading to unintended handling of operational tasks, reminders, or procurement-style actions without clear guardrails.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.