Back to skill

Security audit

auto-prompt

Security checks for vulnerabilities and agentic risk

Overview

This is a planning helper, but it can automatically write project and cross-project memories that may affect future sessions without asking at the time.

Install only if you want this skill to shape general problem-solving behavior and are comfortable with it saving selected conclusions, project conventions, and cross-project preferences into `.workbuddy` memory files. Review those files periodically and avoid using it on sensitive tasks unless the agent asks before persisting anything.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
Findings (7)

Vague Triggers

High
Category
Not specified by scanner
Confidence
96% confidence
Finding

The trigger phrases are broad, common requests that can cause this skill to activate in many ordinary conversations. Because the skill then changes agent behavior, including possible memory writes and external lookups, overbroad activation increases the chance of unintended execution without clear user intent.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
83% confidence
Finding

The activation guidance and trigger examples are specified in Chinese, including explicit phrases the user must say to invoke the skill. The file does not indicate that language choice is optional or offer equivalent user-selectable locale behavior, which can be a locale policy issue if the skill is expected to work without forcing a specific language.

Content

No source excerpt is available for this finding.

Ssd 3

Medium
Category
Not specified by scanner
Confidence
88% confidence
Finding

The skill description explicitly instructs the agent to distill key points into cross-session memory. Even though it tries to limit what is stored, persistent retention of user/task-derived information in plain language can capture sensitive operational context and create privacy or data-minimization issues over time.

Content

No source excerpt is available for this finding.

Ssd 3

Medium
Category
Not specified by scanner
Confidence
97% confidence
Finding

This section operationalizes persistent logging of project conclusions, changes, preferences, and long-term conventions into specific memory files. Because these are durable writes that can influence later sessions and may include sensitive project information, they create a meaningful privacy and integrity risk if performed automatically or without clear consent.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

The skill instructs the agent to write to project and home-directory memory files, including persistent locations, without requiring a clear warning or explicit consent at the time of modification. Persistent writes can alter future agent behavior, leak sensitive task details into storage, and create hard-to-notice cross-session side effects.

Content

No source excerpt is available for this finding.

Intent-Code Divergence

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

The boundary section says the skill is '纯本地、零依赖,不检索内容库也不回写', implying a local-only, dependency-free method. But earlier sections require escalating to external official documentation, T1 communities, and search engines when needed, which is not purely local behavior and does rely on external information sources.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
89% confidence
Finding

Line L09 states that Chinese scenarios should prioritize Chinese sources, which is a natural-language locale preference applied by default. The file does not indicate that users can choose another language or opt out of this behavior.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.