Back to skill

Security audit

domain-navigator

Security checks for vulnerabilities and agentic risk

Overview

This skill is a learning coach that creates a user-controlled Markdown domain map, with no hidden execution, credential use, or background persistence found.

Before installing, note that the skill is designed to keep learning state in a Markdown map and may write that map to a path you provide or confirm. Review the map before pasting it into another AI, because it may contain your goals, background, and learning notes.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Findings (2)

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
90% confidence
Finding

Line L012 states "默认中文,遵循用户语言" (default Chinese, follow the user's language). This sets a specific default language before any user choice, which can conflict with a policy requiring language or locale selection to be user-driven unless clearly justified.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
81% confidence
Finding

The natural-language instructions tell users to paste the map into 'any AI' to continue, but the provided prompt text and workflow are entirely Chinese-language with no opt-in or alternative locale guidance. This can be read as enforcing a specific language/locale experience by default, which matches the policy concern for language or locale constraints without user choice.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.