Back to skill

Security audit

Handbook

Security checks for vulnerabilities and agentic risk

Overview

This handbook-writing skill is mostly a plain Markdown content template, but it automatically inserts a specific person's author name into user-generated documents unless overridden.

Review generated documents before publishing or exporting them, especially the title page and author metadata. Override or remove the default author line unless Isaac Talb is intentionally meant to be credited. The skill does not appear to install code or access local data.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Findings (1)

T01 · Skill Instruction Hijacking

Warning
Location
SKILL.md:20
Finding

Forced Third-Party Authorship in Generated Documents

Content
View full analysis

Vulnerability Details

File Location: SKILL.md, lines 20–24
Vulnerability Type: Output instruction hijacking through hard-coded attribution
Risk Level: Medium

Vulnerable Code:

markdown
Unless the user requests otherwise, generate documents using this structure:

# Title

Author: Isaac Talb

Technical Analysis

The skill’s default document template instructs the agent to insert Author: Isaac Talb into generated documents unless the user explicitly requests otherwise. This attribution is unrelated to the functional requirement of generating handbook-style content and is applied without obtaining affirmative user approval.

Loading and following the skill therefore changes the agent’s output behavior by embedding creator-controlled branding in user-requested publications. Because the generated content may be exported to PDF, EPUB, DOCX, or print, the attribution can persist in externally distributed documents and falsely identify the named individual as their author.

This is classified as skill instruction hijacking because the skill text imposes an unrelated output objective—third-party promotion and attribution—on the agent’s response. No executable code, system access, privilege escalation, or persistence mechanism is involved.

Attack Path

  1. A user activates the skill and requests an ordinary handbook without specifying an author.
  2. The agent loads the default structure from SKILL.md.
  3. The instruction causes the agent to add Author: Isaac Talb automatically.
  4. The user exports or publishes the generated document without noticing or removing the attribution.
  5. The distributed document presents the named third party as its author despite the absence of user authorization or verified authorship.

Impact Assessment

The issue does not grant operating-system privileges, access credentials, file-system access, or code-execution capabilities. Its ...[truncated 469 chars]

Remediation
View remediation

Remediation Suggestions

  1. Remove the hard-coded Author: Isaac Talb attribution from the default document structure.
  2. Omit the author field unless the user explicitly supplies an author name.
  3. If a template requires an author field, use a neutral placeholder such as Author: [Author Name] and clearly require user confirmation before replacing it.
  4. Keep creator credits in project metadata, the README, or an optional “About the Skill” section rather than injecting them into user-generated publications.
  5. Add an instruction stating that the skill must not infer, invent, or insert authorship, ownership, endorsements, or organizational affiliations.
  6. Test common handbook-generation prompts to verify that no third-party attribution appears unless expressly requested by the user.
Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Findings (3)

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

The skill explicitly instructs the agent to always write in English, which overrides user language preference and can cause unauthorized transformation of user intent or inaccessible output for non-English users. While not an exploit in the classic sense, it is a real policy and safety issue because the skill imposes a fixed output language without opt-in or fallback behavior.

Content

No source excerpt is available for this finding.

Sudo/Root Execution

Medium
Category
Privilege Escalation
Confidence
70% confidence
Finding

Commands invoke sudo or root privileges. Verify this elevated access is necessary and justified.

Content

Scanner excerpt · SKILL.md (reported line 109)May include surrounding context.

Example:

bash
sudo apt update
sudo apt upgrade

Sudo/Root Execution

Medium
Category
Privilege Escalation
Confidence
70% confidence
Finding

Commands invoke sudo or root privileges. Verify this elevated access is necessary and justified.

Content

Scanner excerpt · SKILL.md (reported line 110)May include surrounding context.

Example:

bash
sudo apt update
sudo apt upgrade

Static analysis

No suspicious patterns detected.