Back to skill

Security audit

Venture Spawner

Security checks for vulnerabilities and agentic risk

Overview

This is a disclosed sub-agent orchestration skill with high-impact capabilities, but its behavior is coherent with its stated purpose and no hidden code or exfiltration is evident.

Install this only if you want a skill that can coordinate multiple sub-agents and update workspace job state. Review JOB_BOARD.md entries before use, especially jobs involving git push, SSH access, outreach lists, business strategy files, resumes, or other sensitive context.

Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (1)

Vague Triggers

Medium
Confidence
95% confidence
Finding
The direct invocation trigger is broad enough to activate on ordinary user phrasing such as asking to 'spawn an agent,' which can cause unintended execution of this high-privilege orchestration skill. Because the skill can read job boards, spawn sub-agents, pass context, and update workspace state, accidental triggering expands the chance of unauthorized file changes or uncontrolled multi-agent actions.

Static analysis

No suspicious patterns detected.