Back to skill

Security audit

onboard

Security checks for vulnerabilities and agentic risk

Overview

The skill is a focused onboarding flow, but it stores the user's name and work context in persistent personal rules by default without explicit consent.

Review this skill before installing if you do not want onboarding answers saved into persistent personal rules. The tool access is otherwise tightly scoped, but users should be told clearly that name and work context will be remembered and should have an explicit opt-in or easy deletion path.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (3)

Anti-Refusal Statement

High
Category
Anti-Refusal
Confidence
55% confidence
Finding

Skill instructs the agent to omit warnings, disclaimers, or ethical commentary. Stripping safety caveats hides risk from the user and is a common jailbreak preamble.

Content

Scanner excerpt · SKILL.md (reported line 75)May include surrounding context.

md
Run this memory-save flow immediately before continuing:

In the memory-save turn, use only the required direct `cursor_dialog` calls, a one-line saved confirmation, and the Choose Goal question. Do not apologize, mention implementation details, narrate tool behavior, or perform any preparatory discovery/read/search calls.

1. Use `cursor_dialog` with `{ item: "rule", scope: "user", action: "list" }` to list existing personal rules.
2. Use exactly one `cursor_dialog` write call:

Autonomous Decision Making

Medium
Category
Excessive Agency
Confidence
96% confidence
Finding

The skill authorizes autonomous persistence of user data 'without asking a separate permission question,' which removes an important user-consent checkpoint before storing personal information. Even though the stored fields are limited to name and work context, this is still a cross-session data handling action that should require explicit approval.

Content

Scanner excerpt · SKILL.md (reported line 71)May include surrounding context.

md
### 3. Save Memory

After collecting both answers, save the user's name and work context to a personal rule without asking a separate permission question. If the user already clearly asked not to save onboarding details or memory, acknowledge that briefly and continue to Choose Goal without saving.

Run this memory-save flow immediately before continuing:

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
97% confidence
Finding

The skill instructs the agent to persist the user's name and work context to a personal rule without first obtaining explicit consent in the moment. This creates a privacy risk because onboarding details are stored across chats by default, and the skill description does not clearly warn the user that personal data will be saved automatically.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.