Back to skill

Security audit

Auto Body Collision Kit

Security checks for vulnerabilities and agentic risk

Overview

This is a disclosed Nevada-focused marketing content kit with no executable code, persistence, credential access, or hidden agent behavior.

Installers should treat this as a Nevada/Clark County-focused marketing aid, not legal advice. Before publishing generated copy, verify current regulations, shop licenses, certifications, EPA/OSHA status, warranty terms, parts policies, and any location-specific claims.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Findings (4)

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
84% confidence
Finding

The README states the skill generates content specifically for Nevada auto body shops, which imposes a locale constraint in natural language. Under the policy rule, locale restrictions should either offer user choice/opt-in or be clearly documented as a justified region-specific tool; this line frames Nevada scope as part of the product claim rather than an explicit usage limitation or opt-in.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
72% confidence
Finding

The target audience is described as shops in Nevada and agencies serving Nevada clients, which reinforces a fixed locale constraint. While the file suggests Nevada specialization, it does not explicitly present this as a justified regional compliance limitation or ask users to confirm that locale before relying on the skill.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
76% confidence
Finding

This markdown content is written as if the skill should generate output specifically for Henderson, Nevada across all prompts and ads. Under the stated policy, forcing a specific locale without user opt-in can be a natural-language policy violation unless the regional constraint is clearly justified as a region-specific compliance tool.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
88% confidence
Finding

The prompt templates repeatedly prescribe location-specific language such as 'Clark County drivers' and later reference Las Vegas-specific audiences and neighborhoods. This constrains outputs to a specific locale without indicating that users may choose or override the region, which can violate language/locale policy requirements.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.