Back to skill

Security audit

Web Compliance Builder

Security checks for vulnerabilities and agentic risk

Overview

This skill is a transparent website compliance drafting and checklist helper with bounded local scripts and no hidden data access or persistence.

Install only if you want a helper for website policy drafts, compliance checklists, and audit gap reports. Treat its output as drafting and issue-spotting support, not legal advice, and have a qualified professional review high-risk, regulated, cross-border, children-focused, sensitive-data, marketplace, subscription, or AI use cases.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Vulnerability Patterns
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
Findings (4)

Autonomous Decision Making

Medium
Category
Excessive Agency
Confidence
75% confidence
Finding

Skill enables autonomous high-impact decisions without human-in-the-loop verification. Critical operations (destructive commands, financial transactions, data deletion) should require explicit user confirmation.

Content

Scanner excerpt · SKILL.md (reported line 39)May include surrounding context.

md
- Give legal advice.
- Hide uncertainty.
- Assume a platform template (Shopify/Apple/Google) is legally sufficient on its own.
- Claim a page is complete without checking the actual facts of the business.

## Mandatory workflow (in order)

Autonomous Decision Making

Medium
Category
Excessive Agency
Confidence
75% confidence
Finding

Skill enables autonomous high-impact decisions without human-in-the-loop verification. Critical operations (destructive commands, financial transactions, data deletion) should require explicit user confirmation.

Content

Scanner excerpt · research/deep-research-report.md (reported line 186)May include surrounding context.

md
- Give legal advice.
- Hide uncertainty.
- Assume a platform template (Shopify/Apple/Google) is legally sufficient on its own.
- Claim a page is complete without checking the actual facts of the business.

## Mandatory workflow (in order)

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

This is a markdown file, so vague-trigger checks apply. The phrase "Enter AUDIT when the user provides existing pages/URLs or asks to 审计 / audit / review / 合规检查 an existing site" includes generic terms such as "review" and "audit" that overlap with common requests, which could cause unintended invocation without clearer scope or exclusions.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
76% confidence
Finding

Natural-language policy checks apply to all file types. Listing Chinese trigger terms ("审计", "需补充") together with English instructions may imply a locale/language-specific behavior, but the file does not explain whether language selection is user-driven or justified by a region-specific use case.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.