Back to skill

Security audit

Andorra

Security checks for vulnerabilities and agentic risk

Overview

This is a straightforward Andorra travel-planning skill with local preference notes and no executable, network, credential, or hidden behavior found.

Install if you want Andorra-specific travel planning. Before allowing memory, decide whether you want trip style, budget, transport, and travel history kept in ~/andorra/ for future recommendations.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
Findings (6)

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

The instruction "Read this when ~/andorra/ doesn't exist or is empty. Start naturally." does not define a specific user-facing trigger phrase or clear exclusion conditions for when this skill should or should not activate. "Start naturally" is especially vague and could lead to unintended invocation because it provides no narrow scope or negative examples.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
97% confidence
Finding

The skill explicitly tells the agent to save user travel preferences to memory after asking, 'Want me to keep your Andorra preferences handy for future trip ideas?', but it does not clearly disclose retention scope, duration, or what 'main memory' means. This creates a privacy risk because users may consent without understanding that their preferences could persist beyond the current session and influence future interactions.

Content

No source excerpt is available for this finding.

Autonomous Decision Making

Medium
Category
Excessive Agency
Confidence
75% confidence
Finding

Skill enables autonomous high-impact decisions without human-in-the-loop verification. Critical operations (destructive commands, financial transactions, data deletion) should require explicit user confirmation.

Content

Scanner excerpt · SKILL.md (reported line 105)May include surrounding context.

md
## Mistakes to Avoid

- Booking the cheapest room without checking the daily transfer cost in time
- Forgetting that parking can be the hidden tax of a city stay
- Assuming a late-night winter drive is easy just because the distance is short

Autonomous Decision Making

Medium
Category
Excessive Agency
Confidence
75% confidence
Finding

Skill enables autonomous high-impact decisions without human-in-the-loop verification. Critical operations (destructive commands, financial transactions, data deletion) should require explicit user confirmation.

Content

Scanner excerpt · transport.md (reported line 38)May include surrounding context.

md
## Mistakes to Avoid

- Booking the cheapest room without checking the daily transfer cost in time
- Forgetting that parking can be the hidden tax of a city stay
- Assuming a late-night winter drive is easy just because the distance is short

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
78% confidence
Finding

Line L03 says that 'showing basic awareness of the country's own identity helps' immediately after emphasizing Andorra as 'Catalan first,' which can be read as prescribing a specific linguistic or cultural framing for users. Because SQP-3 covers language or locale policy violations, this is a mild concern where the guidance nudges toward one locale identity without explicit user opt-in or a stated choice.

Content

No source excerpt is available for this finding.

Vague Triggers

Low
Category
Not specified by scanner
Confidence
83% confidence
Finding

This markdown file appears to describe when the skill should guide users toward certain dining choices, but it does not define any explicit trigger phrases, invocation conditions, or negative examples. That makes activation scope ambiguous and could cause the skill to match broad travel or food-related requests unintentionally.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.