Back to skill

Security audit

Followup Swarm

Security checks for vulnerabilities and agentic risk

Overview

The skill is a coherent CRM follow-up workflow, but it asks agents to store customer data locally and use external tools without declaring write permission or giving enough privacy and retention controls.

Review before installing. Use it only if you are comfortable with the agent creating persistent local CRM/task files and sending customer/contact/location data to the named workflow tools. Ask the publisher to declare file-write behavior, add consent prompts, and document retention, deletion, and external data sharing before using it with real customer records.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Rogue AgentSelf-Modification, Session Persistence
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
Findings (8)

Scope Creep

High
Category
Not specified by scanner
Confidence
98% confidence
Finding

The deliverables require writing customer archives, follow-up logs, route files, and reports to local directories, but the skill only declares file-read. This misrepresents the skill's effective behavior and can lead to unauthorized storage of sensitive customer data on disk.

Content

No source excerpt is available for this finding.

Scope Creep

High
Category
Not specified by scanner
Confidence
99% confidence
Finding

The skill explicitly instructs creation and modification of local files and directories under ~/.workbuddy/tasks despite declaring only file-read permission. This is a real scope mismatch: if honored by an agent, the skill would induce unauthorized state changes and persistent local data storage beyond its declared capabilities.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The when_to_use field uses broad everyday business phrases such as 客户跟进, 线索管理, and 客户转化, which increases the chance of accidental invocation in unrelated contexts. Unintended activation is risky here because the skill handles CRM workflows, customer data, external services, and persistent file instructions.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

The trigger list is a set of generic keywords without boundaries or disambiguation, making incidental matches plausible during normal conversation. Because the skill is operational rather than informational, accidental invocation could initiate sensitive lead-management steps or expose user data to downstream tools.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The skill handles customer names, phone numbers, emails, addresses, and follow-up history, yet the deliverables section does not provide clear privacy, retention, consent, or access-control guidance. That omission creates a realistic risk of collecting and storing personally identifiable information without adequate user awareness or safeguards.

Content

No source excerpt is available for this finding.

Session Persistence

Medium
Category
Rogue Agent
Confidence
97% confidence
Finding

This duplicated finding points to the same persistent filesystem setup that creates and maintains task artifacts under ~/.workbuddy/tasks. Persistent state can outlive the user’s expectations and enable unintended retention of customer workflow details or later reuse by other processes.

Content

Scanner excerpt · SKILL.md (reported line 87)May include surrounding context.

bash
TASK_NAME="followup-$(date +%Y%m%d)"
mkdir -p ~/.workbuddy/tasks/"$TASK_NAME"
cat > ~/.workbuddy/tasks/"$TASK_NAME"/task-plan.md << 'EOF'
# 任务计划 - 客户跟进

Session Persistence

Medium
Category
Rogue Agent
Confidence
97% confidence
Finding

This duplicated finding points to the same persistent filesystem setup that creates and maintains task artifacts under ~/.workbuddy/tasks. Persistent state can outlive the user’s expectations and enable unintended retention of customer workflow details or later reuse by other processes.

Content

Scanner excerpt · SKILL.md (reported line 87)May include surrounding context.

bash
TASK_NAME="followup-$(date +%Y%m%d)"
mkdir -p ~/.workbuddy/tasks/"$TASK_NAME"
cat > ~/.workbuddy/tasks/"$TASK_NAME"/task-plan.md << 'EOF'
# 任务计划 - 客户跟进

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The skill directs use of social-media lead collection and route-planning services, implying transmission of personal/contact/location data to external tools, but it does not clearly warn users about that data flow. In this context, undisclosed third-party transmission can expose sensitive customer and location information beyond the local session.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.