Back to skill

Security audit

Tdd Workflow

Security checks for vulnerabilities and agentic risk

Overview

This is a frontend TDD guidance skill with no executable payload or hidden high-risk behavior.

Install this if you want the agent to follow a test-first frontend workflow. Expect it to propose or create behavior tests before implementation; if your task is styling-only, documentation-only, backend-only, or pure refactoring, tell the agent not to use this workflow.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
Findings (5)

Skill Enumeration

Medium
Category
Agent Snooping
Confidence
80% confidence
Finding

Skill enumerates or reads other installed skills. Access to other skills' SKILL.md files or the skills directory reveals prompt instructions, capabilities, and secrets that should be invisible to peer skills.

Content

Scanner excerpt · README.md (reported line 10)May include surrounding context.

md
- ID: `fec-tdd-workflow`
- Category: `testing`
- Version: `2.9.0`
- Source: `skills/fec-tdd-workflow/SKILL.md`

## Description

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

The description says to use the skill for implementing new observable frontend behavior or fixing behavior-changing bugs across components, hooks, utilities, API clients, route guards, and user workflows. Although domain-related, this activation scope is very broad and lacks explicit negative examples or narrow invocation phrases, which could lead to unintended invocation for many routine frontend requests.

Content

No source excerpt is available for this finding.

Scope Creep

Low
Category
Excessive Agency
Confidence
75% confidence
Finding

Skill's behavior or capabilities extend beyond its stated purpose. Scope creep allows an agent to perform actions unrelated to its documented functionality, increasing the attack surface.

Content

Scanner excerpt · SKILL.md (reported line 20)May include surrounding context.

md
- Prioritize component interaction Testing Library / Vue Test Utils.
   - Prioritize critical processes across pages Playwright/Cypress.
3. Run the test and confirm that the failure reason is correct and should come from behavior that has not yet been implemented, rather than a syntax, import, or test environment error.
4. Write the minimum implementation that can just pass the test, and do not expand the scope easily.
5. Rerun the test and confirm it turns green.
6. Refactor naming, boundaries and duplication logic while keeping tests passing.
7. Fix bugs and retain regression tests that can reproduce the problem.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
76% confidence
Finding

The instruction requires the agent to output minimum test implementation suggestions first and only then ask for confirmation. This prescribes a fixed interaction behavior that may override user preferences about when to receive guidance versus when to be asked, creating a mild natural-language policy concern around user choice.

Content

No source excerpt is available for this finding.

Vague Triggers

Low
Category
Not specified by scanner
Confidence
90% confidence
Finding

This is a manifest file, so vague-trigger review applies. The description says to use the skill for implementing new observable frontend behavior or fixing a behavior-changing bug across a wide range of targets, but it does not define explicit trigger phrases, invocation constraints, or negative examples, which could lead to unintended activation during common frontend work.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.