Back to skill

Security audit

Pan Pac

Security checks for vulnerabilities and agentic risk

Overview

This is a disclosed Pan Pacific Travel workflow guide that delegates email, calendar, and booking work to other named skills without adding hidden code or persistence itself.

Install this only if you want an agent to help with Pan Pacific Travel email/calendar and booking workflows. Review the separate outlook-entra and lynx-skill permissions carefully, since those downstream skills may access mail, calendars, attachments, OAuth tokens, and booking records.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (2)

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

The activation text is extremely broad: it tells the agent to use this skill for essentially any email, messaging, calendar, event, or booking request in the Pan Pacific context. Because the skill also delegates to Outlook and Lynx, over-triggering could route ordinary communications into a workflow with access to sensitive mail, calendar, attachments, and booking data, increasing the chance of unnecessary data exposure or unintended actions.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
79% confidence
Finding

The skill description uses French while also embedding English directives such as "USE THIS SKILL," which implies a default language behavior without user opt-in. Because the file does not state that language is user-selectable or justified by a region-specific requirement, this may conflict with a language/locale policy requiring choice or documentation.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.