Back to skill

Security audit

Hiring

Security checks for vulnerabilities and agentic risk

Overview

This is a markdown-only hiring guide with disclosed advice about contractors, platforms, payments, and agent delegation, and I found no hidden execution or credential theft behavior.

Before using this skill, set explicit budgets, approval thresholds, credential-sharing limits, and human-review requirements for payments, physical dispatch, and legal or regulated work. The artifact appears safe to install as guidance, but the workflows it describes can create real-world obligations if an agent is separately given platform or payment authority.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Vulnerability Patterns
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Findings (1)

Credential Access

High
Category
Privilege Escalation
Confidence
70% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · SKILL.md (reported line 27)May include surrounding context.

md
4. **Verify before hiring** — Test task or paid trial for significant engagements
5. **Negotiate rates** — Know market rates; prefer fixed-price or milestones over hourly
6. **Contract before work** — IP assignment, NDA, payment terms, termination clause
7. **Structured onboarding** — Access credentials, project brief, communication channels
8. **Milestone payments** — Never 100% upfront; tie payments to deliverables
9. **Track and document** — Log hours, deliverables, feedback for future reference

Static analysis

No suspicious patterns detected.