Back to skill

Security audit

AI Company Registry (EN)

Security checks for vulnerabilities and agentic risk

Overview

This is a static agent-directory skill with no file, network, command, or MCP permissions requested.

This skill appears safe to install as a static registry. Users should be aware that generic phrases like "agent registry" or "C-suite directory" may invoke it in contexts where a more specific skill was intended.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (4)

Vague Triggers

Medium
Confidence
91% confidence
Finding
The trigger phrase "agent registry" is broad enough to match ordinary user requests about organizational structure or status, which can cause unintended skill activation. While the skill has no dangerous permissions, over-broad invocation can still misroute user queries, create confusing responses, and interfere with safer or more appropriate skills.

Vague Triggers

Medium
Confidence
88% confidence
Finding
The trigger phrase "C-suite directory" is ambiguous and could apply to many generic business queries unrelated to this specific registry skill. That ambiguity increases the chance of unintended routing or prompt-surface hijacking in multi-skill environments, even though this file itself does not perform privileged actions.

Natural-Language Policy Violations

Low
Confidence
94% confidence
Finding
The version history mixes English with Chinese text, which implicitly imposes multilingual output/content without indicating user opt-in or a documented locale requirement. Under the language/locale policy, skills should not force a specific language or mixed locale presentation unless the choice is offered or justified.

Vague Triggers

Low
Confidence
80% confidence
Finding
The natural-language examples are framed as broad commands without clear boundaries, making it easier for normal conversation to be interpreted as an invocation. In an agent ecosystem, this can cause accidental activation, response interference, or unintentional disclosure of registry-style data to users who did not explicitly request this skill.

Static analysis

No suspicious patterns detected.