Back to skill

Security audit

AI Company Framework

Security checks for vulnerabilities and agentic risk

Overview

The skill is mostly documentation with no executable code, but it requests broad write, network, and MCP authority while giving under-scoped prompts for installing skills and changing shared state.

Review this skill before installing in a tool-enabled agent. It should only be used in a trusted workspace where you are comfortable with possible file changes, external API use, MCP session/subagent activity, skill installation workflows, shared-state updates, archival logging, and scheduling actions. Require explicit approval before any write, network, installation, activation, or HQ state-change step.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
Findings (8)

Hidden Instructions

High
Category
Prompt Injection
Confidence
60% confidence
Finding

Hidden instructions were detected in comments or invisible text. These could contain malicious directives. Manual review is recommended.

Content

Scanner excerpt · SKILL.md (reported line 1)May include surrounding context.

md
---
name: "AI Company Framework"
slug: "ai-company-framework"
version: "3.0.0"

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The trigger list contains very broad phrases like 'schema compliance', 'generalization', and 'naming conventions' that could match many ordinary requests and cause this skill to activate unexpectedly. Because the skill also declares write, network, and MCP capabilities, accidental invocation increases the chance of unnecessary file modification, outbound API use, or subagent/session actions beyond user intent.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The skill declares read/write file access, network API access, and MCP capabilities, but the user-facing description does not warn that using the skill may modify local files or communicate externally. This can mislead users about operational impact and reduce informed consent, especially in an agent ecosystem where skills may be auto-selected from metadata and triggers.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The instruction 'All content must be in English' imposes a specific language requirement in natural-language guidance. Under the policy, forcing a language without user choice or a clearly justified region-specific constraint is a violation.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

The prompt explicitly directs logging execution metrics, updating shared state, archiving records, and scheduling follow-up actions without warning about data handling, authorization requirements, or side effects. In an environment where an AI agent may have connectors or automation tools, these instructions could trigger unauthorized persistence, state mutation, or disclosure of operational data.

Content

No source excerpt is available for this finding.

Intent-Code Divergence

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

The file presents a copy-paste prompt that instructs an AI to perform operational actions such as loading configuration, updating shared state via HQ, logging metrics, and archiving records, yet labels itself as 'not intended for automated agent invocation.' That mismatch can mislead users or downstream systems into treating the prompt as low risk while it still encourages system-affecting behavior if pasted into an agent with tool access.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
97% confidence
Finding

The trigger keywords are extremely generic terms like 'Standard', 'Module', 'Pattern', and 'Register', which are likely to appear in ordinary user requests. In an agent skill system, this can cause unintended activation, routing confusion, or priority capture by this skill when another skill would be more appropriate, increasing the risk of incorrect behavior across the ecosystem.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The natural-language requirement "English-only for all compiled content" imposes a specific language choice across the skill framework, while only selectively allowing Chinese in trigger keywords. This is a language policy constraint presented without user choice, opt-in, or a clearly justified region-specific compliance reason.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.