Back to skill

Security audit

Skill Design Guide

Security checks for vulnerabilities and agentic risk

Overview

This is a documentation-only skill design guide with no bundled executable code, credential handling, persistence, or hidden data access.

Reasonable to install if you want architecture and review guidance for AI skills. Expect it to add design-checklist context when skill-building topics are discussed; use explicit invocation if your host has loose auto-triggering.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Vulnerability Patterns
  • Rogue AgentSelf-Modification, Session Persistence
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
Findings (9)

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 88)May include surrounding context.

md
| **Brain** | Decision logic, workflow definition | `SKILL.md` |

Self-Modification

High
Category
Rogue Agent
Confidence
85% confidence
Finding

Skill modifies its own code, configuration, or behavior at runtime. Self-modification enables an agent to escalate privileges, disable safety constraints, or install persistent backdoors.

Content

Scanner excerpt · references/agent-design-research.md (reported line 150)May include surrounding context.

md
- **Tools/scripts = Hands** (file I/O, search, specific operations)
- **Knowledge base/directories = Session** (persistent state and data)

Separation means: modify Skill logic without touching the knowledge base; update knowledge base without rewriting the Skill; change directory structure without redesigning the Skill.

---

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

该文件整体以中文呈现,并在标题中直接将其定位为中文版本指南,但正文未说明这是可选的本地化版本,也未向用户或维护者提供语言/locale 选择。根据规则,若技能内容强制特定语言而无明确 opt-in,属于自然语言层面的语言/地区策略问题。

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The documented auto-trigger phrases are broad and overlap with common, non-invocational discussion such as 'design a skill', 'new agent', or 'workflow or agent'. In hosts that activate skills based on loose phrase matching, this can cause unintended skill invocation, inserting extra instructions or context into unrelated conversations and creating prompt-scope confusion.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
90% confidence
Finding

The read_when trigger phrases include broad, generic expressions such as creating or optimizing a skill, which can overlap with ordinary user requests and cause this skill to activate outside its intended scope. Over-broad auto-activation increases the chance that architectural guidance is injected into unrelated conversations, creating prompt-surface expansion and possible workflow confusion rather than direct code-execution risk.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
86% confidence
Finding

The usage examples use broad phrases like 'review this skill' or 'check quality' without defining scope constraints, so an orchestrator may invoke the skill for vague review requests that were not specifically about skill architecture. In context, this is a design-governance skill, so unintended invocation is the main risk: it can misroute user intent, expose irrelevant internal guidance, or interfere with other specialized skills.

Content

No source excerpt is available for this finding.

Vague Triggers

Low
Category
Not specified by scanner
Confidence
86% confidence
Finding

The phrase "load this guide" is common everyday language and, in context, serves as an invocation suggestion for the skill. Because it lacks a narrowly scoped command form or context boundary, it could contribute to unintended activation collisions.

Content

No source excerpt is available for this finding.

Vague Triggers

Low
Category
Not specified by scanner
Confidence
82% confidence
Finding

The trigger examples "Review this skill" and especially "Check quality" are fairly broad natural-language phrases for a markdown skill descriptor. Without clearer scope limits or exclusion examples, they could match general requests that are not specifically about skill architecture review.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
77% confidence
Finding

文件写明“中文版,英文版见 SKILL.md”,表明该技能内容固定为中文,但文中未说明运行时是否允许用户选择语言或根据用户偏好切换。按规则,强制特定语言且无用户选择机制可能构成自然语言层面的语言/地区策略问题。

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.