Back to skill

Security audit

Backend Requirements Handoff

Security checks for vulnerabilities and agentic risk

Overview

This is a documentation handoff skill that may create a requirements Markdown file, with no evidence of hidden execution, credential access, exfiltration, or persistence.

Installers should treat this as a documentation helper. Before use, confirm whether the agent should create a repository file or answer in chat only, and review the generated requirements document before committing it because it may summarize product rules, permissions, and UI behavior.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (7)

Skill Enumeration

Medium
Category
Agent Snooping
Confidence
80% confidence
Finding

Skill enumerates or reads other installed skills. Access to other skills' SKILL.md files or the skills directory reveals prompt instructions, capabilities, and secrets that should be invisible to peer skills.

Content

Scanner excerpt · README.md (reported line 10)May include surrounding context.

md
- ID: `fec-backend-requirements-handoff`
- Category: `maintenance-docs`
- Version: `2.9.0`
- Source: `skills/fec-backend-requirements-handoff/SKILL.md`

## Description

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The README says to use the skill whenever frontend work needs to communicate a wide range of needs to backend teams, and lists broad phrases like 'back-end requirements' and 'API requirements clarification.' Without explicit constraints or negative examples, these triggers could overlap with common product or engineering discussions and cause unintended invocation.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

The manifest description says to use the skill whenever frontend work needs to communicate various needs to backend teams, and includes generic trigger phrases like "back-end requirements" and "API requirements clarification." These phrases are broad enough to overlap with ordinary discussion requests, and the file does not provide explicit exclusion conditions or negative examples to narrow when the skill should or should not activate.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

The manifest description defines very broad activation language such as 'frontend work needs to communicate' and 'API requirements clarification,' which can cause the skill to be invoked outside narrowly intended scenarios. In an agent ecosystem, ambiguous triggers increase the chance of inappropriate routing, causing the skill to shape conversations or outputs where a more suitable skill or no skill should have been used.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
64% confidence
Finding

The description explicitly includes Chinese trigger phrases, while the rest of the skill is written in English and does not explain whether language handling is optional or user-selected. This can create a locale-policy issue because it introduces language-specific activation behavior without documenting user choice or a justified region-specific scope.

Content

No source excerpt is available for this finding.

Missing User Warnings

Low
Category
Not specified by scanner
Confidence
94% confidence
Finding

The skill states that it will write output to a default path unless the user only needs chat replies, but it does not require an explicit confirmation step before modifying the repository. In agent environments, implicit file-writing can cause unintended workspace changes, accidental disclosure in committed docs, or surprise side effects when a user expected analysis-only behavior.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
83% confidence
Finding

The description explicitly states that Chinese triggers include certain phrases, but does not indicate that language selection is optional or user-driven. This can violate language/locale policy expectations because it prescribes a specific language behavior without documenting user choice or a justified regional constraint.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.