Back to skill

Security audit

Birch Bark Container Making Basics

Security checks for vulnerabilities and agentic risk

Overview

This is a non-executable craft-planning skill with disclosed physical and ecological risks, but it overstates what the agent can verify about trees, legality, and safety.

Install only as a planning checklist for a hands-on craft. Do not rely on the agent as an authority for species identification, protected-tree status, land permission, local harvesting law, Indigenous cultural context, or physical safety; verify those independently before harvesting. Be aware that local filesystem logs may store photos, GPS or location notes, and birch-source records.

Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (1)

Vague Triggers

Medium
Confidence
92% confidence
Finding
The activation guidance is broad enough to trigger in many ordinary situations such as wanting cheaper containers, custom storage, or avoiding supply chains, rather than narrowly scoped emergency or educational contexts. Because this skill guides harvesting from live trees and producing load-bearing, water-carrying vessels, over-activation increases the chance that users are steered into unsafe, ecologically harmful, or legally restricted activities without sufficient need or expertise.

Static analysis

No suspicious patterns detected.