Back to skill

Security audit

Prompt Library Gardener

Security checks for vulnerabilities and agentic risk

Overview

This is a prompt-only organizer with clear no-access boundaries, though a few examples are poorly scoped and should be treated as requiring pasted or uploaded user content only.

Installers should treat this skill as safe for organizing prompts that they deliberately paste or upload. Do not allow it to search notes, Notion, chat history, files, drives, email, or browser history unless a separate trusted tool flow asks for explicit permission and scope.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
Findings (10)

Intent-Code Divergence

High
Category
Not specified by scanner
Confidence
97% confidence
Finding

The skill repeatedly states it is a prompt-only workflow that must not search local files, notes, chat history, drives, or private workspaces, but the later usage scenarios describe importing prompts from Notes, Notion, and chat history and testing prompts against the current model. That contradiction can cause an agent to follow the more concrete scenario examples over the earlier safety boundary, leading to unauthorized access attempts or privacy-invasive behavior.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
84% confidence
Finding

The skill description is presented as a direct instruction/value statement in Chinese with no indication that users may choose their preferred language. Under the policy, forcing a specific language or locale without user opt-in is a natural-language policy violation.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The manifest scope is limited to organizing a user-provided prompt collection so prompts can be found, reused, and improved quickly. Lines L19-L21 add a materially different capability: executing prompts against models, scoring outputs, and comparing them to historical benchmarks, which goes beyond cleaning, tagging, deduplication, and indexing.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The manifest sets language: en, and the document otherwise presents the skill as English-only while later including a Chinese scenario. This creates a locale/language policy concern because the skill appears to prescribe a specific language rather than explicitly offering the user a choice or documenting a justified region-specific constraint.

Content

No source excerpt is available for this finding.

Ssd 3

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The scenario explicitly tells the system to import prompts from private Notes, Notion, and chat history even though the skill earlier forbids scanning local files, note apps, chats, drives, or email. In an agentic environment, this can normalize or trigger collection from sensitive personal or workspace sources without the strict user-mediated provision the boundary requires.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
89% confidence
Finding

The trigger keywords are fairly broad and map to common natural-language requests such as 'prompt library' and 'saved prompts', which can increase the chance of accidental or overly broad skill invocation. In an agent ecosystem, unintended invocation can route user data or actions through the wrong skill, causing misfires, confusing outputs, or unnecessary exposure of prompt contents even though this particular skill has no code execution or network access.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
93% confidence
Finding

The acceptance file declares "Language: en," which imposes a language setting in natural language metadata. There is no accompanying note that the user may choose another language or that English-only behavior is required for a documented regional or compliance reason.

Content

No source excerpt is available for this finding.

Vague Triggers

Low
Category
Not specified by scanner
Confidence
80% confidence
Finding

This markdown file includes an example invocation, "Find all my prompts in my notes and organize them," that is phrased in general natural language and could overlap with ordinary user requests. The file does not define a constrained trigger list or negative examples clarifying when the skill should not activate.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
82% confidence
Finding

This scenario switches to Chinese and recommends locale-specific tools and search terms, but the skill does not explain that this is an optional localized example. Without explicit opt-in or clarification, the file mixes language expectations in a way that may violate language/locale policy guidance.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
95% confidence
Finding

The manifest sets "language": "en", which can indicate an English-only constraint. Because there is no accompanying opt-in, user language choice, or region-specific justification in this file, this may violate language/locale policy expectations.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.