Back to skill

Security audit

Inspiration

Security checks for vulnerabilities and agentic risk

Overview

This skill is a curated inspiration directory with user-directed links and no automatic execution or hidden local access.

Install only if you want a reference directory for design and AI-art inspiration. Do not upload confidential, personal, customer, or unreleased images to third-party galleries, and review site terms and licensing before reusing prompts, screenshots, models, or visual assets.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • System Prompt LeakageDirect Leakage, Indirect Extraction, Tool-Based Exfiltration
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
Findings (3)

Direct Prompt Extraction

High
Category
System Prompt Leakage
Content
3. Adapt the prompt elements you like

**From URL:**
1. Most galleries show prompts
2. Civitai always includes generation data
3. Midjourney Showcase links to Discord with prompts
Confidence
85% confidence
Finding
The document encourages 'reverse engineering' prompts from images and adapting prompt elements from publicly visible generations. While framed as inspiration gathering, this can facilitate extraction and reuse of others' creative methods, proprietary prompt recipes, or sensitive generation parameters, especially when combined with links to sites that expose prompt and model metadata.

Vague Triggers

Medium
Confidence
89% confidence
Finding
The 'When to Use' section says the skill applies when a user needs visual references, design inspiration, or examples for creative projects, which is a wide natural-language scope. Although domain-oriented, it does not provide explicit trigger phrases, exclusions, or negative examples to distinguish intended activation from ordinary conversational requests about inspiration.

Missing User Warnings

Medium
Confidence
89% confidence
Finding
The skill instructs users to upload images to third-party services and reuse prompts from public galleries, but it provides no warning that uploaded images may contain sensitive or proprietary content and that prompts can leak confidential workflows, brand strategy, or copyrighted material. In this context, the omission is security-relevant because the skill is explicitly guiding discovery and reverse-engineering workflows through external platforms.

Static analysis

No suspicious patterns detected.