Back to skill

Security audit

shelbys-speech

Security checks for vulnerabilities and agentic risk

Overview

This skill is not plainly malicious, but it asks an agent to read and index very broad private memory, logs, rules, and project archives, then persist activity records and auto-install tooling.

Install only if you intentionally want this skill to use a broad local memory archive for writing. Before running it, limit the source folders, avoid giving it rules, logs, manifests, or unrelated project archives, and require confirmation before package installs, script creation, provenance indexes, or writes back into memory/log files.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
Findings (10)

Vague Triggers

High
Category
Not specified by scanner
Confidence
94% confidence
Finding

The description does not clearly constrain when the skill should activate or when it should not, creating ambiguity in routing. In a skill with broad data access and file operations, loose activation criteria increase the chance of inappropriate invocation during ordinary requests.

Content

No source excerpt is available for this finding.

Missing User Warnings

High
Category
Not specified by scanner
Confidence
96% confidence
Finding

The skill permits access to personal archives, memory stores, and conversation logs as source material without an adequate user-facing privacy warning at the point of use. Users may not reasonably expect that a request to draft a paper could traverse such broad sensitive data sources.

Content

No source excerpt is available for this finding.

Ssd 3

High
Category
Not specified by scanner
Confidence
98% confidence
Finding

Using memory stores and conversation logs as writing material creates a strong natural-language data leakage path: sensitive facts can be copied, paraphrased, summarized, or inferentially exposed in the generated paper. The risk is heightened because the access scope includes system manifests, rules, logs, and project archives that may contain secrets or private operational history unrelated to the writing task.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
88% confidence
Finding

The description does not clearly constrain when the skill should activate or when it should not, creating ambiguity in routing. In a skill with broad data access and file operations, loose activation criteria increase the chance of inappropriate invocation during ordinary requests.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The skill claims the complete memory system is accessed in read-only mode, but later instructions direct writes back into the memory archive and logs. This mismatch weakens trust boundaries and can cause sensitive source material to be modified or polluted despite user expectations of non-destructive access.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

Medium
Category
Not specified by scanner
Confidence
97% confidence
Finding

The workflow grants access not just to the named memory archive but also to broad directories including rules, logs, project folders, and historical documents. That scope is far wider than necessary for paper drafting and materially increases the chance of collecting unrelated secrets, personal data, or internal operational information into prompts or outputs.

Content

No source excerpt is available for this finding.

Intent-Code Divergence

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

The documentation presents full memory-system access as read-only, yet the workflow later instructs the agent to update the memory library with detailed records. This contradiction can lead to unauthorized retention, accidental corruption of source records, and user misunderstanding about how their archives are handled.

Content

No source excerpt is available for this finding.

Ssd 3

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The workflow requires generating an index that maps extracted passages to exact source file paths and segments, which can expose sensitive provenance and internal directory structure in intermediate or final artifacts. Even if the paper text is sanitized, the index itself can reveal where confidential material resides and what was used.

Content

No source excerpt is available for this finding.

Ssd 3

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The logging requirement directs the agent to write detailed execution records, token estimates, encountered problems, and artifact paths back into the memory store. This creates unnecessary persistence of potentially sensitive activity metadata, increasing future disclosure risk and contradicting the notion of minimal, read-only handling.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The skill authorizes autonomous installation/creation of dependencies and tooling before execution, which expands the action scope from document generation into environment modification. This can lead to unreviewed package installation, script placement, and persistence on the host, increasing supply-chain and unintended-change risk even if the stated purpose is benign.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.