Back to skill

Security audit

NPD Validator

Security checks for vulnerabilities and agentic risk

Overview

This product-validation skill is coherent and purpose-aligned, with local file storage of user-provided business data that users should handle carefully.

Install only if you are comfortable with the skill saving product concepts and any internal business data you provide into workspace files for analysis. Avoid providing unnecessary confidential data, review generated data/user_provided files after use, and delete sensitive files when the validation is complete.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Vulnerability Patterns
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Findings (2)

Skill Enumeration

Medium
Category
Agent Snooping
Confidence
83% confidence
Finding

The skill reveals an internal skill path and instructs the agent to read another local skill file, which discloses part of the agent's internal skill layout. While this is not direct code execution, skill enumeration can help an attacker map internal capabilities, target prompt-injection attempts at adjacent skills, or infer hidden workflows and available resources.

Content

Scanner excerpt · SKILL.md (reported line 14)May include surrounding context.

md
# NPD Product Validation Pipeline

You are orchestrating a multi-agent product validation. Read the methodology skill
at `skills/npd-methodology/SKILL.md` before proceeding.

## Step 1: Determine Entry Mode

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The skill instructs the agent to save user-provided internal data to local workspace files without requiring any notice, consent, retention limits, or sensitivity check. Because the skill explicitly solicits sales history, cost sheets, and customer research, this can lead to unexpected persistence of confidential business data and broader exposure to other steps, tools, or later runs that can read workspace contents.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.