Back to skill

Security audit

SOP Systemization — Turn Repetitive Work into Repeatable Process

Security checks for vulnerabilities and agentic risk

Overview

This is a text-only SOP guidance skill with no executable behavior, persistence, credential access, or hidden data flow.

Installers should expect this skill to provide business-process documentation guidance. It may activate on broad SOP-related phrasing, so users should redirect the agent if their request is not about a recurring task, delegation, or automation.

Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (1)

Vague Triggers

Medium
Confidence
92% confidence
Finding
The activation description includes broad, common phrases such as 'everything depends on me' and 'how do I document this', which are likely to appear in many ordinary business conversations. This can cause the skill to trigger outside its intended scope, leading an agent to steer users into SOP/systemization workflows when that was not the user's actual goal.

Static analysis

No suspicious patterns detected.