Back to skill

Security audit

Non-Technical Agent Quickstart

Security checks for vulnerabilities and agentic risk

Overview

This is a plain-language AI workflow guide with no code execution, but users should be careful before pasting private business content into third-party AI tools.

Before installing or following this guide, treat pasted emails, meeting notes, customer details, revenue numbers, investor updates, and internal documents as sensitive. Redact secrets, credentials, personal data, contract details, and confidential customer information unless your organization has approved the AI tool and its retention settings.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Findings (1)

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The skill explicitly tells users to paste emails, inbox contents, meeting notes, and weekly business updates into third-party AI systems, but provides no warning about confidentiality, regulated data, customer information, or retention/training implications. In a non-technical quickstart aimed at founders, this omission is especially risky because users are likely to follow the workflow literally and may expose sensitive internal, customer, financial, or personal data to external providers.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.