Back to skill

Security audit

Ibiza

Security checks for vulnerabilities and agentic risk

Overview

This is a static Ibiza travel and relocation guidance skill with minor wording caveats, not a skill that accesses data, runs code, or changes the user's environment.

Installers should treat this as a destination guide, not authoritative legal or medical advice. Before spending money, relocating, applying for visas, or relying on healthcare information, verify the cited official sources because the skill's data snapshot is from March 2026.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Findings (6)

Ae1

High
Category
analysis-evasion
Content
| Budget food strategy | `food-budget.md` |
Confidence
100% confidence
Finding
Referenced artifact was not completely inspected

Natural-Language Policy Violations

Medium
Confidence
92% confidence
Finding
The guidance treats hearing Spanish spoken by most customers as a signal of authenticity, which introduces a language-based preference that can steer users toward judging venues by patrons' language rather than food quality or cultural practices. In a travel guidance skill, this can reinforce exclusionary heuristics and bias against multilingual or tourist-heavy places that may still be authentic.

Natural-Language Policy Violations

Low
Confidence
86% confidence
Finding
Line L088 states 'Spanish conversation = good sign,' which embeds a preference for a specific language as an indicator of quality. This can be read as a locale/language policy preference without user opt-in or a documented justification.

Natural-Language Policy Violations

Low
Confidence
81% confidence
Finding
This markdown file contains natural-language guidance indicating a de facto language constraint ('May need Spanish') without any opt-in, accommodation guidance, or explicit framing that alternatives may be available. Under the policy rule for language or locale constraints, this is a mild but reportable issue because it normalizes a fixed language requirement rather than offering user choice.

Natural-Language Policy Violations

Low
Confidence
87% confidence
Finding
The text explicitly states 'Spanish language often' for public mental-health services, which is a language/locale limitation presented without alternatives, opt-in, or mitigation steps. This matches the natural-language policy category for language constraints because it may exclude users who do not use Spanish.

Natural-Language Policy Violations

Low
Confidence
82% confidence
Finding
The advice explicitly directs users to English-named Facebook groups as a source of current advice, which reflects an implicit language preference without offering alternatives or noting that other language/local communities may be more appropriate. Under the language/locale policy, content should avoid forcing a specific language unless it is optional or justified.

Static analysis

No suspicious patterns detected.