Back to skill

Security audit

physics-simulator

Security checks for vulnerabilities and agentic risk

Overview

The skill appears to be a sparse physics-simulation wrapper, but it asks for an unspecified API key and points to a missing script, leaving important behavior and data handling unclear.

Review this skill before installing. It is not clearly malicious, but you should not provide a real API key or sensitive experiment data until the publisher supplies the missing simulator script and documents the external service, transmitted data, and intended activation scope.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (2)

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
97% confidence
Finding

The skill's activation guidance is broad enough to trigger on vague requests like general 'science operations' or 'physics related functionality', which can cause the agent to invoke this skill outside clearly intended use cases. Overbroad routing increases the chance of unnecessary external calls, misuse of attached credentials, and user confusion about when simulation or third-party processing is occurring.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

The skill requires an API key and appears to rely on an external simulation service, but the markdown does not clearly warn that user inputs and experiment data may be sent to a third party. This lack of disclosure can lead to unintentional data exposure, improper handling of secrets, and deployment into environments where outbound data transfer or external service use is restricted.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.