Back to skill

Security audit

Global Agent Rules

Security checks for vulnerabilities and agentic risk

Overview

This skill is not malware, but it tells all agents to automatically store and reuse very sensitive personal details in shared memory without clear consent, limits, or deletion controls.

Install only if you intentionally want every agent to have access to and update a shared profile about Donald, including sensitive health, faith, family, accessibility, and financial information. Before use, add explicit consent rules, limit what may be saved, define who can read it, and provide review and deletion controls. VirusTotal and static scan were clean, and no executable malware behavior was found.

Vulnerability Patterns
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
Findings (4)

Description-Behavior Mismatch

High
Confidence
98% confidence
Finding
This section tells every agent to persist and share highly sensitive personal information, including health, finances, family details, faith, and accessibility needs, in a shared profile for broad reuse. In a universal skill loaded by all agents, that creates unnecessary data concentration, expands access to sensitive data far beyond need-to-know, and increases the chance of privacy violations, prompt leakage, or misuse by other skills.

Context-Inappropriate Capability

High
Confidence
97% confidence
Finding
The skill normalizes persistent storage of sensitive personal data as a default behavior even though that is not necessary for a generic behavioral-rules skill. Because this skill applies to all agents, it effectively broadens collection and retention without a clear purpose limitation, which is a classic over-collection and privacy-risk pattern.

Missing User Warnings

High
Confidence
99% confidence
Finding
This section directs agents to record sensitive personal information into shared memory without requiring explicit consent, need-to-know review, or privacy warnings. That creates a substantial privacy and compliance risk because agents may continuously accumulate intimate data and redistribute it across contexts where the user did not expect or authorize reuse.

Ssd 3

High
Confidence
99% confidence
Finding
The shared-memory section explicitly instructs all agents to persist broad categories of highly sensitive data for future reuse, including health conditions, religion, finances, family information, and accessibility traits. Centralizing that information in a universally accessible memory file materially raises the consequences of compromise, prompt injection, overbroad retrieval, and unauthorized secondary use.

Static analysis

No suspicious patterns detected.