Back to skill

Security audit

AI Workflow OS

Security checks for vulnerabilities and agentic risk

Overview

This skill is a disclosed workflow router that mainly tells the agent how to hand multi-step work to specialist skills while preserving user confirmation and state ownership boundaries.

Install this when you want an agent to coordinate complex work across multiple workflow skills. Be aware that implicit routing may activate for broad multi-step requests, so review the selected route and confirm before any state update, upload, migration, deletion, or handoff persistence.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Vulnerability Patterns
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Rogue AgentSelf-Modification, Session Persistence
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
Findings (11)

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
90% confidence
Finding

The skill advertises very broad trigger phrases like 'which skill should handle this' and 'end-to-end AI workflow', which can cause the router to activate for ordinary requests and silently expand into multi-skill orchestration. In an orchestration skill, overbroad invocation scope is dangerous because it can capture requests that did not clearly authorize planning, research, execution, or handoff behavior across multiple state surfaces.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The skill enables implicit invocation but provides no bounded activation criteria, denylist, or exclusion conditions in this file. Because this skill is an orchestrator that routes across multiple workflow surfaces, accidental or overly broad triggering could cause the agent to take control of requests the user did not clearly intend, increasing the chance of unauthorized delegation, scope expansion, or cross-skill state confusion.

Content

No source excerpt is available for this finding.

Autonomous Decision Making

Medium
Category
Excessive Agency
Confidence
75% confidence
Finding

Skill enables autonomous high-impact decisions without human-in-the-loop verification. Critical operations (destructive commands, financial transactions, data deletion) should require explicit user confirmation.

Content

Scanner excerpt · modules/knowledge-intake-governance.md (reported line 24)May include surrounding context.

md
Use source trust levels `trusted`, `allowed`, `review`, and `blocked`. A trusted domain does not make every item current, relevant, or true.

Use evidence states `discovered`, `opened`, `supported`, `corroborated`, `conflicted`, and `cannot-confirm`. Do not promote a search title, snippet, uploaded file, OCR output, or schema-valid record into confirmed truth without checking the relevant content.

使用来源信任等级 `trusted`、`allowed`、`review` 和 `blocked`。可信域名不代表其中每条内容都最新、相关或真实。

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The file consistently presents all instructions in both English and Chinese, indicating a fixed language/locale behavior rather than a user-selected option. The policy requires flagging language or locale constraints when the skill forces a specific language without explicit user opt-in or documented justification.

Content

No source excerpt is available for this finding.

Autonomous Decision Making

Medium
Category
Excessive Agency
Confidence
75% confidence
Finding

Skill enables autonomous high-impact decisions without human-in-the-loop verification. Critical operations (destructive commands, financial transactions, data deletion) should require explicit user confirmation.

Content

Scanner excerpt · SKILL.md (reported line 164)May include surrounding context.

md
4. No evidence means no completion or acceptance claim.
5. `Developer Complete`, `Verified`, and `Accepted` are distinct.
6. Do not change targets, Non-Goals, architecture/data boundaries, production, credentials, or irreversible behavior without clear authority.
7. Do not archive or upload sensitive content without confirmation.
8. Preserve provenance, exact verification outcomes, residual risk, and audit history.
9. When uncertain, use `cannot-confirm`, stage for review, or mark `TBD - Owner Confirmation Required`.
10. Keep bilingual resources available, but answer in the user's language rather than duplicating every sentence.

Autonomous Decision Making

Medium
Category
Excessive Agency
Confidence
75% confidence
Finding

Skill enables autonomous high-impact decisions without human-in-the-loop verification. Critical operations (destructive commands, financial transactions, data deletion) should require explicit user confirmation.

Content

Scanner excerpt · modules/shared-principles.md (reported line 11)May include surrounding context.

md
4. No evidence means no completion or acceptance claim.
5. `Developer Complete`, `Verified`, and `Accepted` are distinct.
6. Do not change targets, Non-Goals, architecture/data boundaries, production, credentials, or irreversible behavior without clear authority.
7. Do not archive or upload sensitive content without confirmation.
8. Preserve provenance, exact verification outcomes, residual risk, and audit history.
9. When uncertain, use `cannot-confirm`, stage for review, or mark `TBD - Owner Confirmation Required`.
10. Keep bilingual resources available, but answer in the user's language rather than duplicating every sentence.

Session Persistence

Medium
Category
Rogue Agent
Confidence
60% confidence
Finding

Skill establishes unauthorized persistence across sessions via cron jobs, startup scripts, or state files. Session persistence allows an attacker to maintain access beyond the current interaction.

Content

Scanner excerpt · references/migration-guide.md (reported line 21)May include surrounding context.

md
## Project Memory / 项目记忆

Keep `daily-workflow` authoritative for explicit checkpoint, wrap-up, and handoff memory. Reuse existing project-owned files; do not create a parallel `Docs/` schema.

明确由 `daily-workflow` 管理 checkpoint、收工和交接记忆。复用项目已有文件,不创建平行 `Docs/` 体系。

Session Persistence

Medium
Category
Rogue Agent
Confidence
60% confidence
Finding

Skill establishes unauthorized persistence across sessions via cron jobs, startup scripts, or state files. Session persistence allows an attacker to maintain access beyond the current interaction.

Content

Scanner excerpt · references/migration-guide.md (reported line 21)May include surrounding context.

md
## Project Memory / 项目记忆

Keep `daily-workflow` authoritative for explicit checkpoint, wrap-up, and handoff memory. Reuse existing project-owned files; do not create a parallel `Docs/` schema.

明确由 `daily-workflow` 管理 checkpoint、收工和交接记忆。复用项目已有文件,不创建平行 `Docs/` 体系。

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
88% confidence
Finding

The headings and table columns are defined as English/Chinese pairs, which imposes a specific language/locale format in the template. There is no indication that users may choose another language or that the Chinese requirement is justified by a region-specific purpose.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
95% confidence
Finding

The template hard-codes section headings in both English and Chinese throughout the file, which imposes a specific language/locale choice rather than offering user selection. Under the policy, fixed language requirements without opt-in or clear region-specific justification can be a natural-language policy violation.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
87% confidence
Finding

The markdown template hardcodes section titles in both English and Chinese throughout the file. This imposes a specific language/locale format without any visible opt-in or explanation that the skill is intended for a bilingual or Chinese-speaking context.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.