Back to skill

Security audit

Citizenship Genealogy

Security checks for vulnerabilities and agentic risk

Overview

This skill is a disclosed genealogy and immigration research assistant, with sensitive personal-data prompts that fit the purpose but should be used carefully.

Before installing, be mindful that genealogy and immigration analysis can involve sensitive information about you and relatives. Share only what is needed, avoid details about living people without consent, treat religion or ethnicity as optional unless legally relevant, and verify any official process with government sources or a qualified professional.

Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Findings (1)

Missing User Warnings

Medium
Confidence
94% confidence
Finding
The workflow instructs collecting sensitive personal data about family members, dates/places of origin, and religion without any minimization, consent, retention, or handling guidance. In a genealogy and citizenship context, this can expose highly sensitive third-party data and create privacy, compliance, and misuse risks if the agent solicits or stores more than necessary.

Static analysis

No suspicious patterns detected.