Back to skill

Security audit

Svg Animation

Security checks for vulnerabilities and agentic risk

Overview

This skill is a coherent SVG animation guidance package with no artifact-backed evidence of hidden access, persistence, credential handling, or unsafe execution.

Install this if you want an agent to apply SVG animation best practices. Be aware it may trigger on broad animation wording, so users should invoke it for SVG-specific motion work when possible.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Vulnerability Patterns
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Memory PoisoningPersistent Context Injection, Context Window Stuffing, Memory Manipulation
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
Findings (7)

Memory Manipulation

High
Category
Memory Poisoning
Confidence
85% confidence
Finding

Skill manipulates agent memory, state, or stored context. Memory corruption can alter personality, override safety rules, or cause unpredictable behavior.

Content

Scanner excerpt · SKILL.md (reported line 139)May include surrounding context.

md
## Constraints

- Prioritize animation `transform`, `opacity` and SVG path attributes; avoid frequent modification of layout-related attributes.
- Interactive controls must retain the visible focus state, and animation cannot replace state expression.
- All non-decorative SVGs must have accessible names; decorative SVGs use `aria-hidden="true"`.
- Default respects `prefers-reduced-motion`, complex animations must provide static or weak motion degradation.
- Don't inline large SVGs into frequently re-rendered components; extract as memoized components or external resources.

Skill Enumeration

Medium
Category
Agent Snooping
Confidence
80% confidence
Finding

Skill enumerates or reads other installed skills. Access to other skills' SKILL.md files or the skills directory reveals prompt instructions, capabilities, and secrets that should be invisible to peer skills.

Content

Scanner excerpt · README.md (reported line 10)May include surrounding context.

md
- ID: `fec-svg-animation`
- Category: `implementation-capability`
- Version: `2.9.0`
- Source: `skills/fec-svg-animation/SKILL.md`

## Description

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

Line L14 says to use the skill for a wide range of motion-related tasks and includes generic trigger terms like 'animation', without clear boundaries or exclusion conditions. This broad natural-language scope overlaps with common frontend requests and does not provide negative examples to clarify when the skill should not activate.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

This is a manifest file, so vague-trigger analysis applies. The description says to use the skill for broad phrases like "implementing or reviewing SVG animation" and lists generic trigger terms such as "SVG animation" and "animation," which can overlap with common development discussion and do not clearly define activation boundaries or exclusions.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The skill description is very broad and covers many adjacent frontend tasks without clear activation boundaries or exclusions. In an agent system, this can cause over-triggering and inappropriate invocation, increasing the chance the skill is used outside its intended scope and influencing outputs in contexts where it should not apply.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
88% confidence
Finding

The description explicitly states that Chinese triggers include specific phrases, which introduces a locale-specific activation path without indicating that this is optional or limited to a Chinese-language environment. Under the policy, language or locale constraints should be opt-in or clearly justified as region-specific.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
88% confidence
Finding

The description explicitly states that Chinese triggers include specific terms, which introduces a language-specific activation behavior. There is no accompanying note that language choice is optional or that the locale restriction is justified, so this may violate language/locale neutrality expectations.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.