Back to skill

Security audit

Customer Feedback

Security checks for vulnerabilities and agentic risk

Overview

This is a markdown playbook for customer feedback with no executable code, with a privacy caveat around recording interviews.

Before using the interview-recording advice, make sure customers give informed consent and understand any third-party transcription or recording tools involved. Store recordings and transcripts securely, limit access, and delete them when no longer needed.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Findings (1)

Missing User Warnings

Medium
Confidence
92% confidence
Finding
The skill advises recording customer interviews and using third-party transcription tools, but it only mentions getting permission to record and does not address storage, retention, vendor handling, sensitive data exposure, or regulatory obligations. This can lead users to collect and transmit personal or confidential information without adequate safeguards, increasing privacy, compliance, and data leakage risk.

Static analysis

No suspicious patterns detected.