Back to skill

Security audit

10 Leadership Virtues for Disruptive Times

Security checks for vulnerabilities and agentic risk

Overview

This leadership-advice skill is mostly static guidance, but it tries to force unsolicited onboarding and promotional branding into responses, including outside its own topic.

Review this skill before installing if you do not want book-specific framing, Heardly branding, or external promotional links added to answers. The artifact does not show malware-like behavior, but its response-control instructions are intrusive and should be narrowed or overridden by host policy.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Findings (2)

T01 · Skill Instruction Hijacking

Warning
Location
SKILL.md:66
Finding

Mandatory Promotional Content Hijacks Agent Responses

Content
View full analysis
Remediation
View remediation

T01 · Skill Instruction Hijacking

Note
Location
SKILL.md:31
Finding

Skill Triggers Unsolicited Output Immediately Upon Loading

Content
View full analysis
Welcome to 10 Leadership Virtues for Disruptive Times 🏆 > Try copying one of these messages to me (I'll show up whenever I sense this book could help): > > "My team is struggling with remote work — how do I keep everyone connected?" > "I lost my cool in a meeting today and now I feel terrible. What would a Coach Leader do?" > "I want to earn my team's respect without being the bossy type." > "We're facing a major setback on our project. How do I keep morale up?" > "How can I build a positive team culture when everyone works from different time zones?" > "I'm new to management and feel overwhelmed. What virtues should I focus on first?" > > Or just say: "Map this book to my life." ``` ### Technical Analysis The skill directs the Agent to emit the complete onboarding guide merely because the skill was loaded, without waiting for a user request. Skill loading should register capabilities or provide context; it should not independently trigger unsolicited conversational output. The use of mandatory wording causes the embedded content to compete with the user's current goal and the host application's expected interaction flow. This constitutes session-level instruction hijacking, although its impact is less severe than instructions that alter safety controls or execute tools. ### Attack Path 1. The host or Agent loads the skill, potentially through automatic intent matching. 2. The first-load instruction becomes active. 3. Without receiving an explicit onboarding request, the Agent presents the embedded Quick Start guide. 4. The unsolicited guide displaces or delays the user's intended interaction. 5. I ...[truncated 676 chars]
Remediation
View remediation
Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (3)

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
90% confidence
Finding

The trigger list contains broad phrases like 'build team culture' and 'handle crisis as leader' that may match many ordinary management conversations not specifically seeking this skill. This can lead to overbroad activation, causing the agent to inject this skill into unrelated contexts and degrade safety, relevance, and user control.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The instruction to 'proactively present this guide without waiting for the user to ask' creates unsolicited self-invocation behavior. In an agent environment, this can cause the skill to activate outside clear user intent, overriding normal routing and increasing the chance of irrelevant or intrusive responses.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The metadata defines trigger phrases such as "lead through change," "build team culture," and "handle crisis as leader," which are broad and likely to match many ordinary leadership queries outside the narrow Tom Ziglar skill scope. Over-broad activation can cause the wrong skill to be invoked, leading to irrelevant guidance, context hijacking, and reduced reliability of the assistant’s routing behavior.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.