Back to skill

Security audit

tlctc-classify

Security checks for vulnerabilities and agentic risk

Overview

This is a documentation-only TLCTC security-analysis taxonomy skill with broad activation wording but no code execution, persistence, installation, or sensitive access.

Install this if you want TLCTC v2.6 to be the default lens for cyber incident and vulnerability classification. Be aware that it may steer generic security-analysis requests toward TLCTC unless you explicitly ask for another framework or a comparison.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Tool MisuseTool Parameter Abuse, Chaining Abuse, Unsafe Defaults
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
Findings (4)

Ae4

Medium
Category
analysis-evasion
Confidence
80% confidence
Finding

Suspicious Unicode normalization or mixed-script content

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

The activation description is extremely broad, triggering on generic analyst requests like 'analyze,' 'classify,' 'deconstruct,' or 'build attack paths' for common security documents. This can cause the skill to activate in contexts where the user did not explicitly request TLCTC, leading to framework hijacking, reduced user choice, and potentially distorted analyses if the forced taxonomy overrides more appropriate methodologies.

Content

No source excerpt is available for this finding.

Unsafe Defaults

Medium
Category
Tool Misuse
Confidence
70% confidence
Finding

Tool defaults are unsafe or overly permissive (e.g. disabled TLS verification, no authentication, world-writable permissions). Unsafe defaults widen the attack surface.

Content

Scanner excerpt · SKILL.md (reported line 1018)May include surrounding context.

md
# PART IV: WORKED EXAMPLES

## Example 1: Feature/Config Misuse (Pure #1)
- **Scenario:** Public object storage bucket is reconfigured to be world-readable
- **Attack Path:** `#1`
- **Outcomes:** `[DRE: C]` (data exposure)
- **Rationale:** No implementation flaw required; attacker advantage comes from legitimate configuration surface

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
99% confidence
Finding

The instruction to 'apply this framework regardless of whether the request explicitly invokes the skill' attempts to override user intent and force a single taxonomy onto unrelated security-analysis tasks. In a tool-using agent, this creates prompt-level scope capture: the skill can dominate analytical behavior, suppress framework selection, and bias outputs even when the user expects neutral or comparative analysis.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.