Back to skill

Security audit

Ai Challenge Assistant

Security checks for vulnerabilities and agentic risk

Overview

This prompt-only hackathon assistant is mostly coherent, but it includes guidance to make invented business and compliance details appear real to judges.

Install only if you are comfortable editing or constraining the skill: require synthetic demo data to be labeled, do not invent real-looking regulatory citations or business metrics, and trigger it only for explicit hackathon or time-limited competition work.

Vulnerability Patterns
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
Findings (6)

Context-Inappropriate Capability

High
Confidence
99% confidence
Finding
The emergency prompt explicitly instructs the model to add specific numbers, system names, and regulatory references to make content 'believable' as a real business scenario. This is deceptive fabrication: it can generate false claims that appear to be factual enterprise, financial, or compliance details, which may mislead judges, customers, or internal reviewers and enable fraud-like misrepresentation.

Vague Triggers

High
Confidence
97% confidence
Finding
The skill is configured to trigger on very broad, common phrases such as general work scenarios and generic requests like scorecards, pitch scripts, or deliverables, even when the user does not explicitly invoke the skill. This can cause unintended activation in unrelated conversations, leading the agent to steer users into creating files, plans, and artifacts they did not ask for, increasing the chance of scope hijacking and unsafe or irrelevant tool usage.

Natural-Language Policy Violations

Medium
Confidence
92% confidence
Finding
The file hard-codes a Chinese font stack and Chinese-only UI guidance as a quality rule, without indicating that locale should follow user preference or task context. This can force generated outputs into a single language/locale, reducing accessibility and potentially causing the agent to disregard user requirements for other languages or regional conventions.

Natural-Language Policy Violations

High
Confidence
99% confidence
Finding
This prompt pattern encourages fabricated specificity as a persuasive tactic, telling the model to insert realistic-seeming operational and compliance details regardless of whether they are true. In a competition assistant context, that increases the risk of producing misleading deliverables that falsely imply real deployments, regulated environments, or validated business metrics.

Ssd 4

Medium
Confidence
97% confidence
Finding
The guidance explicitly recommends rotating AI-generated drafts and confidence badges so repeated clicks appear more authentic to evaluators. This is deceptive behavior that can mislead judges about model grounding, consistency, or real system capability, and it undermines trust in the evaluation process. In the context of a hackathon/pitch assistant, this is more dangerous because the stated purpose is to influence reviewers under time pressure.

Ssd 4

Medium
Confidence
97% confidence
Finding
The Chinese emergency prompt guides the model to build a progressively more convincing 'real business scenario' narrative, which is a form of narrative deception. Even if intended to improve presentation quality for hackathons, it normalizes falsification and can cause users to submit fabricated evidence, compliance references, or business context as if genuine.

Static analysis

No suspicious patterns detected.