Back to skill

Security audit

persian-success-lab

Security checks for vulnerabilities and agentic risk

Overview

This skill is a disclosed Persian-language personal research and experiment logger with scoped web research and persistence behavior aligned to its stated purpose.

Install this only if you want a Persian-first personal research log that may read and update your supplied lab files and use web search against research domains. Keep the lab files in a location you control, avoid storing secrets in the logs, and use explicit commands like today, question, experiment, review, dashboard, or audit to reduce accidental activation.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • YARA SignaturesMalware Match, Webshell Match, Cryptominer Match
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
Findings (14)

Hidden Instructions

High
Category
Prompt Injection
Confidence
60% confidence
Finding

Hidden instructions were detected in comments or invisible text. These could contain malicious directives. Manual review is recommended.

Content

Scanner excerpt · README.md (reported line 86)May include surrounding context.

text
### سوال امروز
### شواهد چه می‌گویند
### آنچه هنوز نامشخص است
### فرضیه
### آزمایش امروز

Hidden Instructions

High
Category
Prompt Injection
Confidence
60% confidence
Finding

Hidden instructions were detected in comments or invisible text. These could contain malicious directives. Manual review is recommended.

Content

Scanner excerpt · README.md (reported line 94)May include surrounding context.

text
### سوال امروز
### شواهد چه می‌گویند
### آنچه هنوز نامشخص است
### فرضیه
### آزمایش امروز

Hidden Instructions

High
Category
Prompt Injection
Confidence
60% confidence
Finding

Hidden instructions were detected in comments or invisible text. These could contain malicious directives. Manual review is recommended.

Content

Scanner excerpt · SKILL.md (reported line 94)May include surrounding context.

text
### سوال امروز
### شواهد چه می‌گویند
### آنچه هنوز نامشخص است
### فرضیه
### آزمایش امروز

Hidden Instructions

High
Category
Prompt Injection
Confidence
60% confidence
Finding

Hidden instructions were detected in comments or invisible text. These could contain malicious directives. Manual review is recommended.

Content

Scanner excerpt · references/source-registry.md (reported line 102)May include surrounding context.

text
### سوال امروز
### شواهد چه می‌گویند
### آنچه هنوز نامشخص است
### فرضیه
### آزمایش امروز

YARA rule 'agent_skill_mcp_tool_poisoning_metadata': MCP/tool metadata poisoning indicators in tool schemas or skill manifests [agent_skills]

High
Category
YARA Match
Confidence
80% confidence
Finding

YARA rule matched a hack tool or exploit indicator (offensive tools, reconnaissance, privilege escalation, or exploit frameworks).

Content

Scanner excerpt · SKILL.md (reported line 3)May include surrounding context.

md
---
name: persian-success-lab
description: Run the user's personal "Success Lab" — a long-running, evidence-based research-and-experiment system investigating what actually causes success and what improves the user's own outcomes. Use this skill whenever the user invokes commands like `today`, `question [topic]`, `experiment [hypothesis]`, `review`, `dashboard`, or `audit` in this context, or asks to run their daily research session, log an experiment, review their research log, see their success-lab dashboard, or challenge their current model of success. Also trigger when the user says things like "run my lab", "امر�

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
97% confidence
Finding

The README states that the skill enforces mandatory Persian-language output. This is a natural-language locale policy constraint that applies to all user-facing interactions, but the file does not indicate user opt-in, alternatives, or a documented region-specific justification.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
98% confidence
Finding

These lines explicitly require all user-facing content to be Persian and limit output regardless of user preference. Because no user choice or opt-in mechanism is described here, this constitutes a natural-language policy issue under the language/locale rule.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
70% confidence
Finding

npx commands without a version suffix (e.g. @1.0.0) create a rug-pull risk if the upstream server is compromised and publishes a malicious update.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The trigger text is broad enough to activate on loose references to research, experiments, dashboards, or a 'model of success' even without exact commands. In an agent system, overbroad activation can cause the wrong skill to intercept unrelated user requests, leading to inappropriate behavior, unwanted file reads/updates, and reduced user control over which instructions govern the session.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
98% confidence
Finding

Mandating Persian-only output by default can override user preference and reduce transparency if the user cannot easily inspect or verify what the agent is doing. While not a classic security bug, it can impair informed consent and safe review of generated research logs or persistent state changes.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
99% confidence
Finding

The language section reinforces a hard rule that all user-facing content must be in Persian unless explicitly overridden. This increases the chance that users or reviewers miss risky actions, incorrect persistence behavior, or misleading summaries because the agent is constrained to a language they may not be expecting in the current environment.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
97% confidence
Finding

The file enforces Persian for all filled values regardless of the user's explicit language preference, which can override user autonomy and create accessibility, comprehension, and safety issues if the user cannot reliably read or verify the output. In a research-and-experiment skill, forcing a single language can also increase the chance that the user misunderstands evidence, experiment instructions, or logged results, especially when precision matters.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The file requires a fixed Persian block at the end of every substantive session and explicitly says to state the no-evidence message in Persian. This is a natural-language locale constraint that applies regardless of user preference, which fits the policy-violation category for forced language without opt-in.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

Line L110 instructs the skill to present dashboard fields in Persian unconditionally. This is a natural-language locale policy issue because it forces a specific language rather than offering the user a choice or documenting a justified region-specific constraint.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.