Back to skill

Security audit

Creative Contracts (Photography & Design)

Security checks for vulnerabilities and agentic risk

Overview

This is a coherent UK creative-contract drafting skill that handles legal and personal details but does not install code, persist, or take actions on the user's behalf.

Before installing, understand that this drafts legal documents but is not a solicitor. Use placeholders where possible, avoid unnecessary personal or sensitive data, and have important or unusual contracts reviewed by qualified UK legal counsel before signing.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (4)

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
89% confidence
Finding

The skill explicitly aims to generate completed contracts ready to send and repeatedly encourages inclusion of full names, addresses, dates of birth, client details, and other personal data. Although it includes GDPR clauses for the contract content itself, it does not warn users to minimise sensitive inputs or avoid pasting unnecessary personal data into the model, which can expose personal information during generation, storage, or sharing workflows.

Content

No source excerpt is available for this finding.

Autonomous Decision Making

Medium
Category
Excessive Agency
Confidence
75% confidence
Finding

Skill enables autonomous high-impact decisions without human-in-the-loop verification. Critical operations (destructive commands, financial transactions, data deletion) should require explicit user confirmation.

Content

Scanner excerpt · SKILL.md (reported line 177)May include surrounding context.

md
- Non-exclusive, one-time use, specified publication, specified issue/date
- Territory: UK or worldwide depending on publication
- Duration: perpetual for that single use
- No modification without approval

*Commercial licence (advertising campaign):*
- Exclusive or non-exclusive

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The listing markets generation of UK-law-grounded contracts as professional, ready-for-signature outputs but does not clearly warn users that the content is not legal advice and should be reviewed by qualified counsel before use. In a legal-document-generation context, users may reasonably rely on inaccurate or incomplete clauses, outdated law references, or poor fit for jurisdiction-specific facts, creating contractual, regulatory, and liability risk.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
95% confidence
Finding

The instruction 'UK English throughout' is a natural-language locale requirement. Under the policy, forcing a specific language or locale without user choice or a clearly documented justification is a policy concern; this file does not present it as an optional preference or explicitly explain the constraint to users as a region-specific limitation.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.