Back to skill

Security audit

Cloud

Security checks for vulnerabilities and agentic risk

Overview

This is a markdown-only consumer cloud storage advice skill with no executable behavior, but users should be careful because some cleanup advice involves permanent deletion.

Install only if you want consumer cloud storage advice. Before following any cleanup step that empties trash, permanently deletes files, removes photos from iCloud, or purges old versions, confirm that the items are backed up somewhere you control and that you understand how syncing affects all devices.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (4)

Missing User Warnings

High
Category
Not specified by scanner
Confidence
97% confidence
Finding

The 'Nuclear option' recommends turning off iCloud Photos and deleting photos from iCloud without clearly explaining Apple sync behavior, device/library interactions, or the risk that users may remove photos they intended to keep. Because photo libraries are often irreplaceable and cloud sync semantics are confusing, this omission creates a significant risk of unintended mass data loss.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The trigger list contains broad, common phrases such as "cloud storage," "share folder," and especially "where are my files," which can match many routine user requests outside the intended scope. This can cause unintended activation of the skill, leading to misrouting, irrelevant guidance, and possible interception of user interactions that should be handled by a different skill.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
90% confidence
Finding

The Dropbox guidance tells users to permanently delete files and purge version history as a way to free space, but it does not warn that these actions can irreversibly destroy data that may still be recoverable. In a cloud-storage cleanup skill, users are especially likely to act quickly on such instructions, increasing the chance of accidental permanent loss of important files.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
88% confidence
Finding

The general tips encourage emptying trash and 'Recently Deleted' across services but do not state that doing so usually permanently removes the last recoverable copy. Since the skill covers multiple cloud providers with different retention behaviors, users may incorrectly assume they can undo these actions later and lose important data.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.