Back to skill

Security audit

directory-submission

Security checks for vulnerabilities and agentic risk

Overview

This skill helps prepare product directory listings and does not install code, persist, or perform submissions automatically.

Before installing, be aware that the skill may read your project-context file and may use web search to fill product details. For confidential or unreleased products, ask the agent to avoid web searches or provide the needed details manually.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (3)

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

The trigger list is unusually broad and includes many common marketing phrases, which can cause the skill to activate for general requests not specifically about directory submission. Over-broad activation increases the chance the agent follows this skill's file-reading and web-search behaviors in contexts where the user did not clearly request them.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
97% confidence
Finding

The skill instructs the agent to read local project-context files automatically, but does not require notifying the user or obtaining consent before accessing workspace files. This can expose sensitive internal product, business, or operational information beyond what the user expected to share in a simple content-generation request.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

The skill directs the agent to search the web for pricing, competitors, and reviews when context is missing, without warning the user that external network requests may occur. This may leak the user's product interest or unreleased project details to third parties and can surprise users who expected an offline-only interaction.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.