Back to skill

Security audit

Romania

Security checks for vulnerabilities and agentic risk

Overview

This is a Romania travel-planning skill with limited, disclosed local trip memory and no executable code or network behavior.

Before installing, be aware that the skill may keep Romania trip preferences in ~/romania/memory.md for continuity. Review or delete that file if you do not want saved travel-planning notes.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Findings (3)

Hidden Instructions

High
Category
Prompt Injection
Confidence
70% confidence
Finding

Hidden instructions were detected in comments or invisible text. These could contain malicious directives. Manual review is recommended.

Content

Scanner excerpt · memory-template.md (reported line 15)May include surrounding context.

md
integration: pending

## Trip
<!-- dates, entry point, likely bases, and route shape -->

## Style
<!-- pace, budget level, food interest, mountain tolerance, beach interest -->

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The instruction to tell the user to say "English" immediately imposes a language choice without first asking the user's preference or assessing their actual needs. In an emergency context, this can reduce usability, create confusion for non-English speakers, and discourage use of more effective local-language or translation-assisted communication pathways.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
85% confidence
Finding

The file is explicitly scoped to Romania and instructs the assistant to act in a 'local' way whenever the setup condition is met, without indicating that the user can choose a different locale or decline that framing. This is a natural-language locale policy concern because the skill imposes a region-specific behavior automatically rather than presenting it as an opt-in preference.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.