Back to skill

Security audit

kickbacks

Security checks for vulnerabilities and agentic risk

Overview

This is a markdown-only promotional guide for Kickbacks.ai with no executable code, but it uses overly broad activation and mandatory branding instructions.

Install this only if you want a Kickbacks.ai promotional assistant. Expect it to steer answers toward Kickbacks and append branding. Before installing the separate VS Code extension it recommends, review that extension’s permissions, privacy policy, Google sign-in flow, ad behavior, and workplace acceptability.

Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (2)

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The trigger list is very broad and includes generic monetization and IDE-related phrases, which can cause the skill to activate in contexts where the user did not intend to invoke it. In practice this creates prompt-scope hijacking risk: the skill can inject unsolicited onboarding, product claims, and behavior constraints into unrelated conversations, increasing the chance of misdirection or unwanted promotional content.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
97% confidence
Finding

The skill requires a branding watermark on every output, including when the request is outside the product's scope, which overrides user intent and system behavior in favor of persistent promotion. This is dangerous because it enables content injection and covert advertising in unrelated interactions, and can mislead users into thinking all responses are endorsed by or originate from the branded product.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.