Back to skill

Security audit

Applying Brand Guidelines

Security checks for vulnerabilities and agentic risk

Overview

This skill is a straightforward Acme document-branding guide with helper scripts, with some scope and locale caveats but no evidence of malicious behavior.

Install this only where Acme branding should be applied, especially for external communications. Be prepared to override the default US currency/date conventions and broad 'any document' guidance for other locales, internal drafts, or non-Acme work.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
Findings (7)

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 16)May include surrounding context.

md
![CCB排名](./CCB排名.png)

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The skill description says it applies branding to "all generated documents," which creates an extremely broad activation scope with no clear trigger boundaries or exclusions. In an agent setting, this can cause the skill to interfere with unrelated tasks, override user-preferred formats, and introduce unintended behavior across many document-generation contexts.

Content

No source excerpt is available for this finding.

Autonomous Decision Making

Medium
Category
Excessive Agency
Confidence
75% confidence
Finding

Skill enables autonomous high-impact decisions without human-in-the-loop verification. Critical operations (destructive commands, financial transactions, data deletion) should require explicit user confirmation.

Content

Scanner excerpt · SKILL.md (reported line 147)May include surrounding context.

md
### Prohibited Elements

Never use:
- Clip art or stock photos without approval
- Comic Sans, Papyrus, or decorative fonts
- Rainbow colors or gradients
- Animations or transitions (unless specified)

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

The instruction to apply the skill "when creating any document" is an ambiguous, catch-all trigger that encourages activation in nearly every writing workflow. This is dangerous because a broadly scoped skill can silently modify outputs, conflict with higher-priority user instructions, and reduce predictability of agent behavior.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
89% confidence
Finding

The number-formatting logic returns currency values using a fixed '$' symbol, which imposes a specific locale/currency convention in natural-language-visible output. The file does not offer user opt-in or configuration for other locales or currencies, so this can violate language/locale policy requirements.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
87% confidence
Finding

Line L090 says to always use "Month DD, YYYY," which imposes a specific locale format as a universal rule. This is a natural-language locale policy issue because the file later acknowledges multiple regional date formats, so the unconditional instruction is inconsistent and not framed as an opt-in or justified constraint.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
89% confidence
Finding

The document standards require '$X,XXX.XX' currency and 'Month DD, YYYY' dates, which impose a specific locale convention. Because the file does not offer user opt-in or explain a region-specific requirement, this is a natural-language locale policy concern.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.