Back to skill

Security audit

Agent

Security checks for vulnerabilities and agentic risk

Overview

This Markdown-only skill is not malware, but it asks agents to infer and remember user behavior patterns without enough user control or memory boundaries.

Review this skill carefully before installing in agents with persistent memory. It is most appropriate where users know the agent may adapt from interaction patterns and where there is a clear way to disable, inspect, or clear learned preferences. Avoid using it unchanged for customer-facing, workplace, or sensitive contexts unless you add explicit consent and memory-retention rules.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (4)

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The skill explicitly encourages inferring user preferences from implicit behavioral signals such as ignored content, energy shifts, rephrasing, and temporal patterns, which amounts to profiling without any disclosure, consent, or memory-boundary guidance. In an agent-definition skill, this is more dangerous because it operationalizes ongoing behavioral surveillance as a default interaction pattern and can lead to covert retention or reuse of sensitive preference data across sessions.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The skill instructs the agent to remember relationship history, trust level, boundaries, and learned patterns over time, but gives no warning that such memory may persist or shape future interactions. In this context, the danger is heightened because the file defines long-term agent behavior, effectively normalizing undisclosed memory and user profiling that may exceed user expectations and erode privacy or autonomy.

Content

No source excerpt is available for this finding.

Autonomous Decision Making

Medium
Category
Excessive Agency
Confidence
75% confidence
Finding

Skill enables autonomous high-impact decisions without human-in-the-loop verification. Critical operations (destructive commands, financial transactions, data deletion) should require explicit user confirmation.

Content

Scanner excerpt · boundaries.md (reported line 5)May include surrounding context.

md
## Proactivity Levels

### Act Without Asking
- Technical implementation within approved scope
- Research, documentation, internal work
- Fixing problems the agent created

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
80% confidence
Finding

The line specifies a fixed communication style ('First-person, casual') as a default identity constraint. Under the policy scope here, forcing a communication style or locale/language preference without user choice can be a natural-language policy concern, and this template does not mention any opt-in or exception handling.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.