Back to skill

Security audit

Rome

Security checks for vulnerabilities and agentic risk

Overview

This is a Rome travel and relocation guidance skill with disclosed local memory, not an executable or deceptive package.

Install only if you want a Rome-specific assistant that may keep local context across sessions. Avoid storing sensitive personal details unless useful, and verify visa, legal, healthcare, cost, and transport information against current official sources.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Rogue AgentSelf-Modification, Session Persistence
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
Findings (21)

Hidden Instructions

High
Category
Prompt Injection
Content
integration: pending | done | declined

## Context
<!-- What you know about their Rome situation -->
<!-- Role: visitor, expat, digital nomad, student, retiree -->
<!-- Nationality: visa implications -->
<!-- Timeline: when visiting, when moving, how long there -->
Confidence
70% confidence
Finding
Hidden instructions were detected in comments or invisible text. These could contain malicious directives. Manual review is recommended.

Vague Triggers

Medium
Confidence
95% confidence
Finding
The activation rule says the skill should be used when a user asks about Rome or Italy for any purpose, which is overly broad and can cause the agent to invoke this skill outside its intended scope. That can lead to irrelevant guidance, unintended overshadowing of more appropriate skills, and increased exposure to inaccurate or stale domain-specific advice such as legal, visa, or tax information.

Session Persistence

Medium
Category
Rogue Agent
Content
# Memory Template — Rome

Create `~/.rome/memory.md` with this structure:

```markdown
# Rome Memory
Confidence
88% confidence
Finding
The skill instructs creation of a persistent file in the user's home directory (`~/.rome/memory.md`) to retain conversation-derived personal context across sessions. This creates a session-persistence mechanism that can accumulate sensitive personal data such as nationality, timeline, and preferences without clear consent, retention limits, or minimization controls, increasing privacy and data exposure risk.

Missing User Warnings

Medium
Confidence
94% confidence
Finding
The skill instructs the agent to modify MEMORY.md to persist a new skill entry, but it does not require a clear warning that a user file will be changed at the time of the write. Even though it asks for consent first, silent or poorly signposted persistence into user-controlled files can violate user expectations and create integrity/privacy concerns around stored preferences and profile data.

Ssd 3

Medium
Confidence
89% confidence
Finding
The skill encourages the agent to accumulate personal profile details over time, including nationality, budget, language ability, and relocation status, using natural conversation. Persistent collection of these attributes can create privacy risks and unnecessary profiling, especially if the user is not clearly told what will be stored, why it is needed, and how to stop retention.

Natural-Language Policy Violations

Low
Confidence
76% confidence
Finding
The document presents prices in EUR throughout, which imposes a specific locale/currency convention in natural language without any opt-in or clarification. Under the stated policy, locale-specific presentation can be a violation when it forces a particular locale assumption and is not explicitly documented as region-specific.

Natural-Language Policy Violations

Low
Confidence
78% confidence
Finding
The phrase "Call (Italian preferred)" imposes a language preference in the instructions without presenting alternatives or making it optional. Under the language/locale policy, content should avoid steering users toward a specific language unless there is opt-in or clear justification.

Natural-Language Policy Violations

Low
Confidence
76% confidence
Finding
Line L020 states 'Italian preferred, English usually OK,' which nudges users toward a specific language. Under the policy, forcing or strongly prescribing a language without explicit opt-in can be a locale/language policy concern, even if the rest of the content is benign.

Natural-Language Policy Violations

Low
Confidence
83% confidence
Finding
The file states 'Italian essential' as a blanket requirement, and later reinforces this with 'Learn Italian' and 'Cannot stress enough.' Under the policy, forcing a specific language without user opt-in can be a natural-language locale violation unless the constraint is clearly justified as region-specific compliance or optional.

Natural-Language Policy Violations

Low
Confidence
89% confidence
Finding
Line L075 includes the parenthetical phrase "not loud Americans," which singles out a nationality in a derogatory stereotype. This is a natural-language policy concern because the guidance could be conveyed without targeting a specific national group.

Natural-Language Policy Violations

Low
Confidence
79% confidence
Finding
Line L104 includes a natural-language statement that public schools 'require language,' which functions as a locale/language constraint in the guidance. Because the document does not offer alternatives, accommodations, or clarify this as context-dependent, it may conflict with the policy against forcing a specific language without user opt-in.

Natural-Language Policy Violations

Low
Confidence
78% confidence
Finding
The phrase 'Very few "regular" residents left' is a natural-language quality issue because it frames some residents as more legitimate than others. This kind of wording can reflect an organizational policy concern around respectful, non-exclusionary language in user-facing content.

Natural-Language Policy Violations

Low
Confidence
77% confidence
Finding
This markdown file presents neighborhood recommendations entirely for Rome, using localized assumptions about housing, transit, and lifestyle, but does not explicitly state that the content is intended only for users seeking Rome-specific advice. While region-specific content can be justified, the file does not document that scope, which may create a locale constraint without clear user opt-in or context.

Natural-Language Policy Violations

Low
Confidence
42% confidence
Finding
This file repeatedly describes who lives in areas using labels like 'wealthy Roman families,' 'older expats,' and similar social categorizations. However, SQP-3 is limited to language or locale policy violations, and this content does not clearly force a language or locale, so confidence is low.

Natural-Language Policy Violations

Low
Confidence
90% confidence
Finding
The section states 'Italian is Essential' and presents language use as necessary for integration, bureaucracy, relationships, and culture. This is a natural-language locale preference that does not offer opt-in or acknowledge alternative language needs, which can conflict with language-choice policy expectations.

Natural-Language Policy Violations

Low
Confidence
96% confidence
Finding
The phrase 'Learn Italian (non-negotiable for real integration)' is a direct normative language requirement. Because it does not offer alternatives or frame the statement as optional user guidance, it fits the policy category for forced language or locale assumptions.

Natural-Language Policy Violations

Low
Confidence
88% confidence
Finding
Line L133 labels the anti-violence hotline as "(Italian)", which communicates a language constraint for an important safety resource without noting any alternative language options or advising users how to obtain support if they do not speak Italian. Under the policy, locale or language limitations should be opt-in or clearly justified with user choice where possible.

Natural-Language Policy Violations

Low
Confidence
78% confidence
Finding
The instruction says the agent should remember to use this skill for Italy or Rome queries, which creates a persistent routing preference tied to a broad topic area. While not directly dangerous on its own, it can bias future behavior without granular user control and may cause the skill to be invoked more often than the user intended.

Ssd 3

Low
Confidence
87% confidence
Finding
The skill directs the agent to persist the user's response, including a declined-integration status, in memory. Recording preference/state can be reasonable, but persisting it in a user memory file without a clear storage notice and review mechanism still creates a privacy and user-control concern.

Natural-Language Policy Violations

Low
Confidence
79% confidence
Finding
Line L042 says 'Rarely problematic for Western tourists,' which introduces a broad nationality/cultural distinction in natural-language guidance. This can be read as differential treatment advice based on origin rather than neutral, policy-based travel information.

Natural-Language Policy Violations

Low
Confidence
81% confidence
Finding
The guidance tells users to assume English is not widely spoken and explicitly instructs them to learn basic Italian phrases. This promotes a specific language expectation without offering user choice or framing it as optional preference.