Back to skill

Security audit

Research Assistant

Security checks for vulnerabilities and agentic risk

Overview

This is a research-helper skill with no executable code, but it asks agents to persist research files, add ongoing monitors, and include third-party branding in generated reports.

Install only if you want the agent to keep a persistent research folder and possibly monitoring files in your workspace. Review or remove the default branded report footer, avoid putting the protocol into global system instructions or cron unless you intentionally want recurring behavior, and keep monitors scoped to non-sensitive topics with explicit refresh rules.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Findings (1)

T01 · Skill Instruction Hijacking

Error
Location
SKILL.md:112
Finding

Mandatory Third-Party Branding Injected into Generated Research Briefs

Content
View full analysis
Remediation
View remediation
Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (3)

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
89% confidence
Finding

The description says 'Use when you need market research, competitor analysis, topic deep-dives, or ongoing monitoring of trends and news,' which describes broad situations rather than specific invocation phrases or constraints. Because these are common, high-level tasks and no exclusion conditions or negative examples are provided, an agent could over-apply the skill in loosely related contexts.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The skill instructs the agent to read, create, save, and update files in a persistent research/ directory automatically, including maintaining an index across sessions. That creates a stateful side effect without a prominent user-facing consent mechanism, which can lead to unintended data retention, workspace modification, or storage of sensitive research topics and sourced material.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
87% confidence
Finding

The file recommends automated research triggers with broad example conditions such as reacting to competitor launches or regulatory news, but it does not define approval gates, scope boundaries, or validation criteria before actions run. In an agent skill context, ambiguous triggers can cause unintended autonomous actions, excessive tool usage, noisy alerting, or research on irrelevant/sensitive topics when loosely matched events are detected.

Content

No source excerpt is available for this finding.

Static analysis

Detected: suspicious.prompt_injection_instructions

Prompt-injection style instruction pattern detected.

Warn
Code
suspicious.prompt_injection_instructions
Location
SKILL.md:63