Back to skill

Security audit

Ransomware Preventer

Security checks for vulnerabilities and agentic risk

Overview

This skill is a coherent ransomware-defense API wrapper, but it asks users to send sensitive security-posture details to an external service without enough data-handling or scoping guidance.

Review this before installing if your organization treats architecture, security-tool inventory, or maturity assessments as confidential. Use redacted or minimal inputs, avoid real user IDs unless needed, and confirm the third-party service's privacy, retention, and access-control practices before sending production security details.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (3)

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

The skill explicitly documents collection of organizational assessment data, session identifiers, timestamps, and optional user-tracking data, but provides no privacy notice, data minimization guidance, retention limits, or handling constraints. In a security-focused skill, this is especially risky because the submitted environment details can reveal high-value infrastructure, security tooling, and gaps that could become sensitive reconnaissance material if logged, shared, or retained insecurely.

Content

No source excerpt is available for this finding.

External Transmission

Medium
Category
Data Exfiltration
Confidence
80% confidence
Finding

The skill directs users to transmit sensitive organizational security assessment data to an external domain, but the documentation provides no trust boundary warning, vendor assurance details, or guidance on what sensitive data should be excluded. Because the data includes security posture, deployed systems, tools, and identifiers, sending it to a third-party endpoint increases exposure to data leakage, unauthorized retention, or supply-chain risk if the service is compromised or insufficiently governed.

Content

Scanner excerpt · SKILL.md (reported line 266)May include surrounding context.

md
## References

- **Kong Route:** https://api.mkkpro.com/security/ransomware-preventer
- **API Docs:** https://api.mkkpro.com:8078/docs

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
84% confidence
Finding

The POST operation accepts broad organizational assessment data and appears designed to generate personalized security recommendations, but the manifest provides no invocation constraints, safety boundaries, or exclusion conditions. In an agent setting, this can allow unconstrained forwarding of sensitive enterprise context to the endpoint and may enable misuse beyond the intended defensive scope, including processing unnecessary or overbroad user-supplied data.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.