Back to skill

Security audit

Paris

Security checks for vulnerabilities and agentic risk

Overview

This is a static Paris guide skill with broad but disclosed travel and relocation advice, and it does not include code execution, hidden data access, or persistence.

Reasonable to install as a Paris reference guide. Before relying on it for prices, visas, healthcare, transport fares, safety, or business setup, verify against current official or local sources because much of the content is static and some entries are dated.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (7)

Vague Triggers

Medium
Confidence
93% confidence
Finding
The trigger text says the skill should be used when a user asks about Paris 'for any purpose,' which is extremely broad and does not define meaningful boundaries for invocation. This can cause unintended activation for casual mentions of Paris or requests outside the intended travel/residency/career guidance scope.

Missing User Warnings

Low
Confidence
90% confidence
Finding
The file gives safety ratings and neighborhood warnings as factual guidance without noting that crime conditions, policing, and local conditions change over time and can vary block by block. Users may over-trust this information when making housing or travel decisions, especially because the skill is explicitly positioned as practical local guidance for visitors and residents.

Natural-Language Policy Violations

Low
Confidence
75% confidence
Finding
The file includes prescribed French phrases for vegetarian, vegan, and gluten-free communication, which may imply a fixed language approach. Under the policy, forced language or locale without opt-in can be a concern unless the regional constraint is clearly documented and justified.

Missing User Warnings

Low
Confidence
81% confidence
Finding
This markdown file explicitly promotes apéro spots and alcohol consumption, including BYOB drinking locations, but provides no warning about responsible drinking, local regulations, or avoiding drinking and driving. For a user-facing skill description, this is a missing safety disclosure related to user wellbeing and lawful behavior.

Natural-Language Policy Violations

Low
Confidence
81% confidence
Finding
This local-services guide highlights 'English-speaking' and 'Hospitals with English Support' as preferred options, which can be interpreted as privileging a specific language without user opt-in. Under the stated policy, language-specific guidance should either offer a choice or clearly justify the locale constraint.

Natural-Language Policy Violations

Low
Confidence
85% confidence
Finding
The statement "Ignoring French | Helps enormously with hiring, customers" introduces a language-specific expectation in prescriptive guidance without offering an alternative or clarifying that it depends on the user's context. This can conflict with language/locale neutrality expectations because it nudges users toward a specific language without opt-in.

Natural-Language Policy Violations

Low
Confidence
83% confidence
Finding
Line L026 uses absolute language: 'Always say "Bonjour" ... to anyone,' which effectively imposes a specific language expectation. Under the policy, forcing a language without user opt-in can be a natural-language policy violation, and the text does not frame this as optional or offer alternatives.

Static analysis

No suspicious patterns detected.