Back to skill

Security audit

Complaint

Security checks for vulnerabilities and agentic risk

Overview

This is a simple complaint-handling guidance skill with no executable code, hidden behavior, or unusual permissions.

Install this if you want an agent to help structure complaint-handling SOPs. When using it with real customer complaints, avoid pasting unnecessary personal data and keep any dashboard or data-ingestion work within your organization's privacy and compliance rules.

Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (1)

Vague Triggers

Medium
Confidence
87% confidence
Finding
The skill description is broad enough that an agent could invoke it in many loosely related situations without clear boundaries or preconditions. In practice, this can cause over-triggering, leading the agent to provide complaint-handling workflows when they are not appropriate, which may expose sensitive customer data handling guidance in the wrong context or interfere with safer, more specific skills.

Static analysis

No suspicious patterns detected.