Back to skill

Security audit

Route Protection

Security checks for vulnerabilities and agentic risk

Overview

This skill provides normal frontend route-protection guidance and does not show hidden execution, persistence, or data access behavior.

This appears safe to install as a guidance skill. Use it for frontend route guards and redirect behavior, while continuing to enforce real authorization on APIs, server components, loaders, and server actions.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Vulnerability Patterns
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Memory PoisoningPersistent Context Injection, Context Window Stuffing, Memory Manipulation
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
Findings (5)

Memory Manipulation

High
Category
Memory Poisoning
Confidence
85% confidence
Finding

Skill manipulates agent memory, state, or stored context. Memory corruption can alter personality, override safety rules, or cause unpredictable behavior.

Content

Scanner excerpt · SKILL.md (reported line 52)May include surrounding context.

md
if (status === "loading") return <RouteLoading />;
  if (status === "anonymous") {
    return <Navigate to="/login" replace state={{ from: location }} />;
  }
  if (requiredPermissions.length > 0 && !canAccess(user, requiredPermissions)) {
    return <Navigate to="/403" replace />;

Skill Enumeration

Medium
Category
Agent Snooping
Confidence
80% confidence
Finding

Skill enumerates or reads other installed skills. Access to other skills' SKILL.md files or the skills directory reveals prompt instructions, capabilities, and secrets that should be invisible to peer skills.

Content

Scanner excerpt · README.md (reported line 10)May include surrounding context.

md
- ID: `fec-route-protection`
- Category: `implementation-capability`
- Version: `2.9.0`
- Source: `skills/fec-route-protection/SKILL.md`

## Description

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The README says to use the skill for a long list of broad frontend topics such as redirects, middleware, and login state handling, and also mentions generic Chinese triggers. This creates ambiguous activation conditions because it does not clearly distinguish when the skill should be invoked versus when adjacent frontend routing or auth topics should use another skill, and it provides no negative examples or explicit constraints.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

This manifest description says to use the skill when implementing or reviewing a wide list of common frontend topics such as redirects, middleware, and login state handling. Those terms are broad and frequently arise in ordinary development discussions, but the manifest does not provide explicit trigger phrases, exclusions, or negative examples to distinguish when the skill should or should not activate.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The description activates on a wide range of frontend auth and routing topics without clear boundaries for when the skill should or should not be used. Overly broad triggers can cause the skill to be invoked in inappropriate contexts, increasing the chance that route-protection guidance is applied where stronger backend authorization or different security controls are required.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.