Back to skill

Security audit

University Solution Explainer

Security checks for vulnerabilities and agentic risk

Overview

This is a tutoring-format skill for explaining university STEM problems; its behavior is coherent and no hidden execution, data access, persistence, or destructive action was found.

Before installing from the README command, prefer a pinned or trusted installation path when available. Expect the skill to shape responses for academic problem explanations; avoid enabling it globally if broad tutoring triggers would interfere with more specialized skills.

Vulnerability Patterns
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (1)

T08 · Insecure Dependencies

Warning
Location
README.md:91
Finding

Unpinned Third-Party Installer and Mutable Skill Source

Content
View full analysis
Remediation
View remediation
add ``` 2. Replace the mutable skill reference with an immutable commit hash or cryptographically verified release. 3. Publish and verify integrity hashes or signed release artifacts before installation. 4. Review the resolved package, transitive dependencies, and lifecycle scripts before recommending the command. 5. Use a lockfile or equivalent dependency manifest where the installation mechanism supports it. 6. Disable package lifecycle scripts during installation when they are unnecessary and the package manager supports doing so. 7. Run installation in a sandbox or least-privilege environment without access to production credentials or sensitive user files. 8. Document the exact CLI version, source revision, expected integrity value, and verification procedure so users install the same artifact that was audited. ]]>
Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (3)

Rp1

Medium
Category
MCP Rug Pull
Confidence
70% confidence
Finding

npx commands without a version suffix (e.g. @1.0.0) create a rug-pull risk if the upstream server is compromised and publishes a malicious update.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The README says activation occurs by sharing a problem and lists triggers like "Explain this question," "Break down this problem," and "Solve this with me." These phrases are generic, overlap with ordinary conversation, and the file does not provide exclusion conditions or narrower constraints to distinguish when this skill should activate versus other general-help skills.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The trigger phrases are broad and overlap with many normal tutoring or study-assistance requests, which can cause the skill to activate outside a narrowly intended context. Over-broad activation increases the chance of inappropriate routing, prompt interference with other safer/more-specific skills, and accidental application to content the skill was not designed to handle.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.