Back to skill

Security audit

Pg Jobs

Security checks for vulnerabilities and agentic risk

Overview

This is a transparent ProxyGate job-marketplace guide, but users should treat its job and escrow commands as real account actions.

Install only if you intend to use ProxyGate job-marketplace workflows. Confirm the job ID, amount, deadline, wallet/account, and whether escrow will be locked or released before running create, claim, submit, accept, reject, cancel, deposit, withdraw, or listing-management commands. Be careful with ambiguous requests like generic gigs or freelance tasks because the trigger wording is broad.

Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (1)

Vague Triggers

Medium
Confidence
89% confidence
Finding
The skill description uses very broad trigger phrases such as "job board," "gig," and "freelance task," which can cause the agent to invoke this skill in contexts far beyond ProxyGate-specific requests. That increases the chance of inappropriate tool selection and unintended job-marketplace actions, especially because this skill includes commands that create, claim, submit, accept, reject, and cancel escrow-backed jobs.

Static analysis

No suspicious patterns detected.