Back to skill

Security audit

gpt-go

Security checks for vulnerabilities and agentic risk

Overview

This is a disclosed productivity skill that makes the assistant act more decisively after explicit invocation, with no hidden network access, credential use, destructive behavior, or cross-session persistence.

Install only if you want an explicitly invoked mode where the assistant moves faster, asks fewer routine questions, and treats brief follow-ups like 'continue' or 'fix it' as permission to keep working on the current task. Avoid using it for sensitive, production, financial, privacy, or permission-changing work unless you are prepared to enforce confirmations at those boundaries.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
Findings (7)

Tp4

High
Category
MCP Tool Poisoning
Confidence
98% confidence
Finding

The declared description presents a conversational control skill that switches the assistant into an execution-oriented mode when invoked and persists that mode across the conversation. The supplied code does something materially different: it is a local synchronization/generation utility that parses markdown headings from SKILL.md and writes selected content into gateway-prompt.txt. There is no logic for detecting explicit invocation such as /gpt-go, no conversation-state persistence, no runtime assistant behavior change, and no boundary handling beyond copying text sections. The file read/write behavior is also undeclared. This is a clear description-to-behavior mismatch.

Content

No source excerpt is available for this finding.

Vague Triggers

High
Category
Not specified by scanner
Confidence
96% confidence
Finding

The skill instructs the assistant to treat many short, common phrases as authorization to continue a current task, which weakens confirmation boundaries and increases the chance of unintended mode activation or continuation. In a system with tools or side effects, ambiguous phrases like 'do it' or 'fix it' can cause the assistant to proceed without sufficiently fresh, task-specific user consent.

Content

No source excerpt is available for this finding.

Vague Triggers

High
Category
Not specified by scanner
Confidence
98% confidence
Finding

The skill explicitly treats vague, common phrases like 'continue', 'start', and 'you handle it' as ongoing authorization to act, which weakens consent boundaries and can cause the agent to perform unintended actions without clear, task-specific confirmation. In a persistence-oriented execution mode, this increases the chance of overreach across multiple turns, especially when user intent is ambiguous or context shifts.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
85% confidence
Finding

The file hard-codes Chinese phrases alongside English as authorization triggers for continued execution, but does not indicate that the user opted into multilingual handling or that the locale behavior is region-specific. This creates a natural-language policy concern because language behavior is being expanded by default rather than offered as a choice.

Content

No source excerpt is available for this finding.

Autonomous Decision Making

Medium
Category
Excessive Agency
Confidence
90% confidence
Finding

The skill biases the assistant toward acting first and gathering information directly from the environment instead of asking the user, which encourages autonomous tool use and reduces opportunities for user oversight. In environments with filesystem, repo, or service access, this can lead to unnecessary data exposure, over-collection, or unintended modifications before intent and scope are fully confirmed.

Content

Scanner excerpt · SKILL.md (reported line 93)May include surrounding context.

md
## Tool bias

Use tools to inspect and act whenever possible.
Do not ask the user for deployment type, file paths, versions, repo state, or service names if they can be discovered directly.

## Anti-patterns

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
88% confidence
Finding

The file instructs the assistant to operate in a terse Chinese-language style (for example, "直接干,少废话" and "回复尽量短") without indicating user choice or opt-in. This can violate language/locale policy when users have not explicitly requested that language or communication style.

Content

No source excerpt is available for this finding.

Missing User Warnings

Low
Category
Not specified by scanner
Confidence
87% confidence
Finding

The code writes content to gateway-prompt.txt with fs.writeFileSync, which modifies a file on disk. Although there is a post-action log message, there is no prior comment, docstring, or explicit warning in this file that the skill will overwrite or create this output file.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.