Back to skill

Security audit

Html Anything

Security checks for vulnerabilities and agentic risk

Overview

This skill mostly builds local HTML reports, but some built-in source guides ask users to expose highly sensitive credentials or private archives without enough safeguards.

Install only if you are comfortable with a skill that reads private source material and may produce HTML files containing the underlying records. Avoid using its Discord token workflow, be cautious with browser-history extensions, review/redact sensitive exports before conversion, and treat generated HTML as private unless you intentionally create a sanitized version.

Vulnerability Patterns
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
Findings (4)

T09 · Insecure Skill Coding Practices

Error
Location
prompts/sources/discord.md:12
Finding

Discord session token exposed to an unverified third-party exporter and command-line arguments

Content
View full analysis
-c -f Json ``` ``` ### Technical Analysis The Skill instructs users to retrieve a live Discord authorization token from browser developer tools and disclose it to a community-maintained exporter. This token is a bearer credential: any process or person obtaining it may be able to act with the authenticated account's access until the token is revoked or expires. The CLI example places the token directly in a command-line argument. Depending on the operating system and shell configuration, it may consequently appear in: - Shell history files. - Process listings and process-monitoring tools. - Terminal recordings, screenshots, or support logs. - Audit or endpoint-monitoring telemetry. - Crash reports generated by the exporter. The recommended executable is downloaded from a mutable third-party release channel without a pinned version, checksum, signature-verification procedure, or sandboxing requirement. A compromised release could read and transmit the supplied token and any exported messages. The operation exceeds minimum privilege because converting an existing JSON or CSV file to HTML does not require the Skill itself to obtain or handle a reusable account credential. ### Attack Path 1. A user asks the Agent to convert a Discord channel without supplying ...[truncated 1036 chars]
Remediation
View remediation

T08 · Insecure Dependencies

Error
Location
prompts/sources/browser-history.md:38
Finding

Unvetted browser extensions are recommended for access to complete browsing history

Content
View full analysis
Remediation
View remediation

T08 · Insecure Dependencies

Warning
Location
prompts/styles/paper-trail.md:231
Finding

Unpinned npm package execution through npx

Content
View full analysis
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Note
Location
prompts/styles/_design.md:109
Finding

Default Google Fonts requests contradict offline and no-network privacy guarantees

Content
View full analysis
` (Space Grotesk + Plus Jakarta Sans, the only two web-font calls allowed): ```html ``` ``` The main Skill separately states: ```markdown - Inline CSS and JS in the HTML. - No external JS/CDN dependencies unless the user explicitly allows them. - The only default external font call is the Google Fonts import from `prompts/styles/_design.md`. ``` ### Technical Analysis Generated reports may embed browsing, financial, contact, chat, health, location, or other sensitive records. Despite repeated claims that outputs are offline-capable or make no network calls, the shared design guidance directs generated pages to preconnect to and load resources from Google-controlled domains. Opening such a page can disclose connection metadata including the viewer's IP address, request time, browser characteristics, and potentially referrer information. It also reveals that the generated artifact was opened. The `preconnect` elements initiate third-party connectivity even before the font stylesheet is required. This request is unnecessary for the declared functionality because system fonts or locally bundled font files can provide a usable HTML report without contacting a third party. ### Attack Path 1. The Skill generates an HTML report containing sensitive source-derived data and the shared font imports. 2. The user opens the report while connected to the ...[truncated 765 chars]
Remediation
View remediation
Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
Findings (37)

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 184)May include surrounding context.

md
Read `prompts/styles/_design.md`, `prompts/styles/catalog.json`, and the

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 203)May include surrounding context.

md
Read `prompts/styles/_design.md`, `prompts/styles/catalog.json`, and the

Context-Inappropriate Capability

High
Category
Not specified by scanner
Confidence
98% confidence
Finding

The skill tells the user how to extract a Discord user token from DevTools and use it with an exporter. A Discord user token is a sensitive authentication credential, and instructing users to retrieve it is an account-access enabling step unrelated to the core HTML rendering function. In this context, the skill expands from document conversion into credential acquisition guidance, which materially increases the risk of account compromise, token leakage, or policy-violating access.

Content

No source excerpt is available for this finding.

Missing User Warnings

High
Category
Not specified by scanner
Confidence
96% confidence
Finding

The instruction states that the full archive is embedded in the HTML, creating a self-contained portable file that can expose entire mail contents, identities, thread history, and attachment metadata if redistributed or mishandled. This is especially risky because users may treat HTML reports as harmless summaries, while this one effectively packages a complete mailbox in a shareable format.

Content

No source excerpt is available for this finding.

Anti-Refusal Statement

High
Category
Anti-Refusal
Confidence
80% confidence
Finding

Skill instructs the agent to omit warnings, disclaimers, or ethical commentary. Stripping safety caveats hides risk from the user and is a common jailbreak preamble.

Content

Scanner excerpt · prompts/styles/catalog.json (reported line 187)May include surrounding context.

json
"accent": "#e63946",
      "coreScaffold": ["full-viewport lanes", "live ranks", "kinetic activity body", "telemetry footer", "evidence pits"],
      "requiredPrimitives": [".kinetic-arena", ".rank-lane", ".activity-body", ".telemetry-footer", ".evidence-pit"],
      "avoid": ["static participant table", "generic chat transcript", "ranking without caveats"]
    },
    {
      "id": "timeline-story",

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The invocation guidance is extremely broad ('make a webpage', 'turn this into HTML', 'visualize/analyze this') and overlaps with many ordinary user requests. That can cause the skill to activate in contexts the user did not intend, leading it to inspect files, folders, or URLs and transform potentially sensitive material into shareable HTML without sufficiently explicit consent.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The skill promises to turn files, folders, URLs, and datasets into HTML, but the top-level description does not prominently warn that it may inspect local content and embed source data into the generated artifact. This creates a real privacy and data-handling risk because users may not realize that sensitive records could be read, summarized, or included client-side in a shareable page.

Content

No source excerpt is available for this finding.

Autonomous Decision Making

Medium
Category
Excessive Agency
Confidence
84% confidence
Finding

The instruction to avoid asking the user questions by default, combined with automatic handling of URLs, files, folders, and exports, increases the chance of the agent acting on ambiguous or sensitive inputs without informed confirmation. In this skill, that autonomy is more dangerous because the output is a polished shareable artifact that may preserve or expose underlying private data.

Content

Scanner excerpt · SKILL.md (reported line 66)May include surrounding context.

md
| URL | Fetch or inspect the URL when possible, then create a page from the page/repo/article content. |
| Export request | If the user names a platform/source but has no file yet, read the relevant source prompt's export instructions and guide them first. |

Do not ask the user to pick a style by default. Use `auto`.

Ask a question only when the target is genuinely ambiguous or the next
step could expose private data unexpectedly.

Autonomous Decision Making

Medium
Category
Excessive Agency
Confidence
80% confidence
Finding

Skill enables autonomous high-impact decisions without human-in-the-loop verification. Critical operations (destructive commands, financial transactions, data deletion) should require explicit user confirmation.

Content

Scanner excerpt · SKILL.md (reported line 195)May include surrounding context.

md
mood board.

5. **Choose auto style.**
   Pick the page style internally. Do not ask the user to choose unless
   they explicitly want style options.

6. **Extract the style contract.**

Intent-Code Divergence

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

The prompt instructs the generated page to state that the vault 'never left your machine,' but the source content is in fact sent to the agent during generation. This creates a misleading privacy guarantee that can cause users to share highly sensitive notes under false assumptions about data handling.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
87% confidence
Finding

The prompt requires literal section labels to be visible in the rendered DOM, and later mandates exact English phrases for several outputs. This imposes a specific language on the generated experience without any user opt-in or documented locale justification.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
90% confidence
Finding

These lines require the model to use exact English phrases such as "outside the reference range printed on this row," "date listed on this document," and "not present in this record." Because no alternative locale behavior or user choice is offered, the skill hard-codes a language policy across all outputs.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The skill instructs users to install third-party browser extensions/add-ons to export browsing history, but it does not warn that these tools may receive access to one of the most sensitive data sources on a user’s device. Because browser history can reveal identity, habits, work activity, finances, health interests, and account portals, encouraging extension installation without a privacy-risk warning can expose users to unnecessary collection or misuse by the extension publisher.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The content provides operational steps for obtaining and using a Discord user token without clearly framing it as a sensitive secret or warning the user not to expose it. Even if the tool is commonly used, omission of credential-handling safeguards can lead users to paste live tokens into unsafe places, retain them insecurely, or misunderstand the sensitivity of the credential.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
87% confidence
Finding

The skill explicitly requires full-text search across subjects and body text in a generated HTML artifact, which materially increases exposure of sensitive email content if the file is shared, synced, or opened in an unsafe context. While the footer mentions local generation, it is not a strong, prominent warning about the privacy implications of embedding searchable personal communications into a portable document.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
97% confidence
Finding

The prompt directs users to export and upload Google Maps Saved/Starred places from Google Takeout, which can reveal highly sensitive personal location preferences, routines, travel interests, home/work associations, and private notes. Because the skill is specifically designed to transform that data into HTML and gives step-by-step export instructions without any privacy warning, minimization guidance, or consent checkpoint, it increases the chance users will expose sensitive personal data more broadly than intended.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

The prompt explicitly instructs the generated HTML to include a searchable full event drill-down with title, organizer, attendee list, location, description, and recurrence details. For calendar exports, those fields commonly contain sensitive personal or business information, so rendering them broadly without any privacy warning, redaction guidance, or minimization creates a real data-exposure risk if the output is shared or hosted.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
87% confidence
Finding

The export instructions encourage users to retrieve and load a complete My Clippings.txt file before clearly foregrounding that it contains years of highly personal reading highlights, notes, and bookmarks. In a skill designed to ingest and render intimate user data, failing to present an up-front sensitivity warning increases the risk of inadvertent over-collection and user disclosure without informed consent.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
82% confidence
Finding

The instructions state that the keyword clusterer skips non-Latin scripts and excludes them from the thematic roll-up, which creates a locale-dependent feature limitation without offering the user a choice or opt-in. This is a natural-language policy concern because users with non-Latin content are silently denied equivalent thematic analysis based on language/script.

Content

No source excerpt is available for this finding.

Intent-Code Divergence

Medium
Category
Not specified by scanner
Confidence
98% confidence
Finding

The file makes a strong privacy/offline claim for sensitive Kindle highlights, but later permits a Google Fonts network request. That exception undermines the stated no-network posture and can leak user IP address, user agent, timing, and page-open metadata to a third party when the HTML is viewed, which is especially concerning given the intimate nature of the embedded reading data.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
97% confidence
Finding

The skill explicitly requires that unmasked email addresses be embedded in the inlined client-side DATA object while only masking them at render time. This means anyone with access to the generated HTML can trivially recover all raw addresses via View Source, devtools, saved-file inspection, or downstream re-sharing, so the privacy control is cosmetic rather than substantive.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

This section explicitly instructs the page to expose every raw location ping in a browseable drill-down, including timestamp and precise lat/lon, which materially increases privacy and re-identification risk. Although the file includes earlier privacy warnings, the UI guidance here normalizes displaying the most sensitive records without requiring masking, minimization, or stronger on-page warnings at the point of access.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The Slack export instructions tell users how to extract channel data, including public channels and potentially DMs/private channels, but do not prominently warn that exports contain other users' messages, names, timestamps, reactions, and metadata that may be sensitive or legally restricted. In a skill whose purpose is to convert exported content into shareable HTML artifacts, this omission materially increases the risk of privacy violations, unauthorized disclosure, and mishandling of third-party communications.

Content

No source excerpt is available for this finding.

Intent-Code Divergence

Medium
Category
Not specified by scanner
Confidence
97% confidence
Finding

The footer promises that the transcript 'never left your machine' and was 'generated locally,' but the skill instructions also require LLM-written summaries and classifications derived from transcript content. If the implementation uses a remote model or API, this creates a materially false privacy representation that can mislead users into sharing sensitive meeting transcripts under incorrect assumptions about data handling.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

This prompt encourages importing a Twitch export that may contain highly sensitive behavioral, chat, and financial activity data, but it does not present a clear upfront warning before acquisition and conversion. Because the page is designed to feel celebratory and explicitly downplays privacy concerns, users may share or preserve an HTML artifact containing embedded full-history data without fully appreciating the exposure risk.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.