Back to skill

Security audit

Whisky Search & Information

Security checks for vulnerabilities and agentic risk

Overview

This skill is a read-only whisky lookup helper that uses WhiskySpace API data and does not install code, request credentials, or persist data.

Before installing, understand that whisky-related searches and URL lookups can be sent to WhiskySpace's public API. Avoid putting private information into search terms, and use explicit whisky-related wording when you want this skill to run.

Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (1)

Vague Triggers

Medium
Confidence
92% confidence
Finding
The trigger guidance includes broad natural-language examples like 'tell me about Macallan' and 'where did this link come from', which can cause the skill to activate for loosely related user queries and route conversations into external lookup behavior unexpectedly. Overly broad invocation increases the attack surface for prompt-routing mistakes, data overfetching, and tool misuse, even though the skill itself is read-only and constrained to a specific API.

Static analysis

No suspicious patterns detected.