Back to skill

Security audit

solution-research

Security checks for vulnerabilities and agentic risk

Overview

This skill is a research workflow that is broad and resource-heavy, but its behavior is disclosed, purpose-aligned, and does not show hidden persistence, credential use, destructive actions, or exfiltration.

Install this only if you want agents to perform deep, source-heavy technical research. Before using it, set clear limits for time, budget, language, allowed sources, and whether cloning repositories or using tools like gh CLI and yt-dlp is acceptable.

Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (2)

Vague Triggers

Medium
Confidence
91% confidence
Finding
The activation condition is broad enough that the skill may be invoked for many loosely related tasks involving 'choosing solutions' or 'comparing products,' which can unnecessarily steer the agent into a rigid workflow. In this skill, that over-broad trigger is more concerning because the workflow then imposes mandatory exhaustive research behavior, increasing the chance of misapplication, wasted resources, and policy-conflicting behavior when a simpler or user-directed response would be more appropriate.

Natural-Language Policy Violations

High
Confidence
95% confidence
Finding
The skill explicitly instructs the agent to conduct research in English without offering user choice or documenting a necessary constraint. This can override user preferences and lead the agent to exclude relevant non-English sources, distort results, or behave inconsistently with the user's language and accessibility needs; in a research skill, that is especially risky because source selection directly affects the quality and fairness of conclusions.

Static analysis

No suspicious patterns detected.