Back to skill

Security audit

Prompt Engineering Lab

Security checks for vulnerabilities and agentic risk

Overview

This is a prompt-engineering guide with broad activation phrases but no hidden execution, credential access, persistence, or destructive behavior.

Reasonable to install if you want a prompt-engineering reference. Be aware it may activate for fairly general prompt-help requests, and independently verify any time-sensitive model, compliance, or tool claims before using them in production or regulated work.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (2)

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

The English trigger phrases are broad, generic requests such as 'improve my prompt' and 'my AI keeps giving wrong answers' that overlap with many normal conversations about AI usage. This can cause unintended skill activation in unrelated contexts, potentially steering users into this skill when they did not request it and interfering with skill routing or policy boundaries.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The Chinese trigger phrases are similarly broad and include common terms like '提示词优化' and '写一个系统提示词' without contextual constraints. Because these are widely used phrases in ordinary AI discussions, they increase the chance of accidental invocation, especially in multilingual environments where routing precision may already be weaker.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.