Back to skill

Security audit

Dependency Upgrade

Security checks for vulnerabilities and agentic risk

Overview

This is a frontend debugging workflow skill with no executable payload, but users should redact sensitive diagnostic data before saving reports.

Install only if you want a structured frontend debugging workflow. Before saving or sharing generated reports, review and redact secrets, cookies, authorization headers, request bodies, environment values, internal URLs, customer data, and screenshots that may reveal private information.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
Findings (11)

Skill Enumeration

Medium
Category
Agent Snooping
Confidence
80% confidence
Finding

Skill enumerates or reads other installed skills. Access to other skills' SKILL.md files or the skills directory reveals prompt instructions, capabilities, and secrets that should be invisible to peer skills.

Content

Scanner excerpt · README.md (reported line 10)May include surrounding context.

md
- ID: `fec-debug-framework`
- Category: `review-quality`
- Version: `2.9.0`
- Source: `skills/fec-debug-framework/SKILL.md`

## Description

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

Line L14 lists many broad activation cues such as "debugging," "troubleshooting," and "error reporting" without clearly constraining when the skill should or should not activate. It also does not provide negative examples or explicit scope boundaries, increasing the risk of unintended invocation for general help requests.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The skill description includes very broad trigger terms such as debugging, troubleshooting, exceptions, white screens, and request failures, which can cause the skill to activate for many ordinary engineering conversations. Over-broad activation increases the chance the agent will enter a diagnostic workflow unnecessarily, leading to unneeded file inspection, command suggestions, or report generation in contexts where the user did not explicitly request this skill.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

The description contains very broad trigger terms such as 'debug', 'troubleshooting', 'error reporting', and 'exceptions', which can match routine conversation and cause the skill to activate outside its intended scope. In agent-routing systems, overbroad activation increases prompt-surface area and can unintentionally inject this skill's instructions into unrelated tasks, degrading control boundaries and enabling misuse.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The description includes very broad activation phrases such as 'debug', 'troubleshooting', 'runtime errors', and similar generic failure terms. In agent-routing systems, this can cause the skill to be invoked in many unrelated contexts, increasing the chance of unintended tool use, over-collection of context, or unsafe delegation to a skill the user did not explicitly request.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

The template directs the agent to save a diagnostic report that may include logs, stack traces, screenshots, network traces, environment variables, and status snapshots, all of which can contain secrets, personal data, tokens, internal URLs, or customer information. Because it gives no instruction to redact sensitive fields, obtain user review, or minimize collected data before persisting it to disk, it creates a realistic risk of unintended data retention and disclosure.

Content

No source excerpt is available for this finding.

Scope Creep

Low
Category
Excessive Agency
Confidence
75% confidence
Finding

Skill's behavior or capabilities extend beyond its stated purpose. Scope creep allows an agent to perform actions unrelated to its documented functionality, increasing the attack surface.

Content

Scanner excerpt · SKILL.md (reported line 10)May include surrounding context.

md
## Purpose

Use an evidence-driven triage, collection, hypothesis, verification, and remediation process to locate front-end faults and avoid relying on intuition to expand the scope of changes.

## Procedure

Scope Creep

Low
Category
Excessive Agency
Confidence
75% confidence
Finding

Skill's behavior or capabilities extend beyond its stated purpose. Scope creep allows an agent to perform actions unrelated to its documented functionality, increasing the attack surface.

Content

Scanner excerpt · SKILL.md (reported line 150)May include surrounding context.

md
## Purpose

Use an evidence-driven triage, collection, hypothesis, verification, and remediation process to locate front-end faults and avoid relying on intuition to expand the scope of changes.

## Procedure

Missing User Warnings

Low
Category
Not specified by scanner
Confidence
84% confidence
Finding

The skill instructs saving a diagnostic report to a timestamped file but does not warn that the report may contain sensitive project details such as stack traces, request metadata, state snapshots, or internal paths. In a debugging skill, this context makes the issue more plausible because the workflow explicitly collects potentially sensitive operational data before writing it to disk.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
72% confidence
Finding

The description explicitly introduces a language-specific trigger set with the phrase "Chinese triggers include," but the listed terms are predominantly English. This is a natural-language policy issue because it imposes or documents a locale-specific behavior inconsistently and without giving the user a clear language choice or explaining the constraint.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
72% confidence
Finding

Line L04 explicitly states "Chinese triggers include..." in the activation description, introducing a language-specific behavior in natural language. There is no accompanying indication that language selection is optional or that the skill is intentionally limited to a Chinese-language deployment context.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.