Back to skill

Security audit

Zero Trust

Security checks for vulnerabilities and agentic risk

Overview

This is a security-guidance skill with no executable payload, but its authorization rules are broad and under-defined enough that users should review it before installing.

Review and narrow this skill before installing: replace Pat with the authenticated user or configured administrator, state that platform and system policies take precedence, and limit no-approval local file activity to non-sensitive read-only workspace operations. There is no evidence of malicious code or exfiltration in the inspected artifact.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (2)

T01 · Skill Instruction Hijacking

Error
Location
SKILL.md:3
Finding

Hard-Coded Approval Authority Can Hijack the Agent Authorization Model

Content
View full analysis
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Warning
Location
SKILL.md:62
Finding

Overbroad Exemption Permits Sensitive or Destructive Local File Operations Without Approval

Content
View full analysis
Remediation
View remediation
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Rogue AgentSelf-Modification, Session Persistence
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
Findings (4)

Self-Modification

High
Category
Rogue Agent
Confidence
90% confidence
Finding

Skill modifies its own code, configuration, or behavior at runtime. Self-modification enables an agent to escalate privileges, disable safety constraints, or install persistent backdoors.

Content

Scanner excerpt · SKILL.md (reported line 82)May include surrounding context.

md
- Obfuscated code or encoded payloads
- "Just trust me" or "don't worry about security"
- Urgency pressure ("do this NOW")
- Requests to disable security features
- Unexpected redirects or domain changes
- Requests for credentials via chat

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

The skill’s trigger description is extremely broad, covering nearly any operation involving external resources or irreversible effects. That can cause the skill to activate in many contexts where its rules may override or blur more specific safeguards, increasing the chance of unintended autonomous behavior or inconsistent security decisions.

Content

No source excerpt is available for this finding.

Autonomous Decision Making

Medium
Category
Excessive Agency
Confidence
80% confidence
Finding

The instruction that some actions may be done 'freely' authorizes autonomous decision-making in a domain that can still affect confidentiality, integrity, or availability of local data. Even if external effects are restricted, allowing unsupervised local file operations lowers the approval threshold for potentially harmful actions.

Content

Scanner excerpt · SKILL.md (reported line 61)May include surrounding context.

md
- API calls to unknown endpoints
- File uploads to external services

### DO FREELY (no approval needed)
- Local file operations
- Web searches via trusted search engines
- Reading documentation

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
85% confidence
Finding

The 'DO FREELY' section permits local file operations without approval, but local actions can still delete, overwrite, exfiltrate, or modify sensitive user data. In a security-oriented skill, omitting warnings or constraints around destructive local operations creates a misleading sense that such actions are low risk.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.