Back to skill

Security audit

Pangolin SafeYield

Security checks for vulnerabilities and agentic risk

Overview

This is a text-only investment analysis workflow with no executable code or privileged system access, though its broad triggers and financial-advice framing deserve care.

Install only if you want an agent to provide structured stock and ETF analysis using public web searches. Review all outputs carefully before acting, because it can generate specific allocation and trade-plan suggestions and may activate from broad trigger words.

Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (2)

Vague Triggers

Medium
Confidence
89% confidence
Finding
The trigger list includes broad phrases such as generic investment-analysis terms that are likely to appear in ordinary user conversations. This can cause unintended invocation of the skill, leading the agent to inject domain-specific instructions and financial advice workflows into unrelated contexts, which is riskier here because the skill is long, prescriptive, and advisory in nature.

Vague Triggers

Low
Confidence
95% confidence
Finding
Single-word English triggers like 'Pangolin' and especially 'SafeYield' are overly broad and can collide with normal discussion, product names, or market commentary. Accidental activation could steer the assistant into producing unsolicited investment-analysis behavior and authoritative-sounding recommendations, increasing misuse and user-confusion risk in a financially sensitive domain.

Static analysis

No suspicious patterns detected.