Back to skill

Security audit

Data Analysis Reporting

Security checks for vulnerabilities and agentic risk

Overview

This is a coherent markdown-only data analysis skill that guides reports on user-provided business data without hidden execution, persistence, or data export behavior.

This skill is reasonable to install for structured business-data analysis. Users should still avoid sharing unnecessary PII, confirm any database access is intentionally provided, and treat recommendations as analytical guidance rather than financial, tax, investment, or audit-grade advice.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Memory PoisoningPersistent Context Injection, Context Window Stuffing, Memory Manipulation
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
Findings (4)

Memory Manipulation

High
Category
Memory Poisoning
Confidence
80% confidence
Finding

Skill manipulates agent memory, state, or stored context. Memory corruption can alter personality, override safety rules, or cause unpredictable behavior.

Content

Scanner excerpt · SKILL.md (reported line 32)May include surrounding context.

md
- "What decision does this analysis need to support?"
   - "What time period or comparison matters most?"
   - "Who is the audience for this report?"
   If the user provides clear context, skip to step 2.

2. **Ingest and validate** — parse the data, detect column types, run quality checks
   - Auto-detect: column types (numeric, date, categorical, text)

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
89% confidence
Finding

This markdown test case presents the request "I have sales data. Can you analyze it?" and labels it as an ambiguous request, but it does not provide clear trigger constraints or exclusion conditions. Because the phrase is very broad and overlaps with common everyday analysis requests, it could contribute to unintended invocation if reused as a skill trigger example without more specificity.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
83% confidence
Finding

The instruction says to default currency formatting to "$X,XXX.XX" when the user's format is not known. This imposes a U.S.-style locale/currency convention by default rather than offering a locale choice or neutral formatting, which is a natural-language locale policy concern.

Content

No source excerpt is available for this finding.

Vague Triggers

Low
Category
Not specified by scanner
Confidence
91% confidence
Finding

This markdown file defines activation-like routing cues in the 'Template Selection Guide' using broad phrases such as 'quick overview', 'which is better', and 'how are we doing'. These phrases are common in everyday requests and the file does not provide exclusion conditions or negative examples, which could cause the wrong template to be selected unintentionally.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.