Back to skill

Security audit

Risk Assessment Compliance

Security checks for vulnerabilities and agentic risk

Overview

This skill appears to be a legitimate hosted security-check API, but it can send user-provided targets to a third party and lacks clear limits for authorized or sensitive URLs.

Use this only for websites or applications you own or are explicitly authorized to test. Do not submit private intranet, staging, customer-specific, or confidential URLs unless your organization approves sending them to the listed third-party API provider. Review the provider's privacy, retention, and acceptable-use terms before using it for sensitive assets.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (4)

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

The skill instructs users to submit a target URL for assessment but does not clearly warn that the provided URL will be sent to an external third-party service. This creates a transparency and data-handling risk because users may submit internal, sensitive, or non-public endpoints without realizing they are disclosing them to an outside provider.

Content

No source excerpt is available for this finding.

External Transmission

Medium
Category
Data Exfiltration
Confidence
88% confidence
Finding

The skill references an external API endpoint, indicating that user-supplied targets will likely be transmitted off-platform to api.mkkpro.com for processing. In a security-assessment context, this is sensitive because the submitted URLs may reveal internal infrastructure, unreleased applications, or other confidential assets to a third party.

Content

Scanner excerpt · SKILL.md (reported line 103)May include surrounding context.

md
## References

- **Kong Route:** https://api.mkkpro.com/compliance/risk-assessment
- **API Docs:** https://api.mkkpro.com:8014/docs

Vague Triggers

Low
Category
Not specified by scanner
Confidence
89% confidence
Finding

This is a manifest-style OpenAPI file, so vague-trigger checks apply. The only invocation cue is a generic security-check endpoint and summary, but the file does not specify when this skill should or should not be used, nor does it provide narrowing context or exclusion conditions.

Content

No source excerpt is available for this finding.

Vague Triggers

Low
Category
Not specified by scanner
Confidence
81% confidence
Finding

The request schema accepts an unconstrained string URL and the skill description broadly claims to assess websites and applications, with no restrictions on scheme, host type, ownership, or environment. In an agent context, this can enable scanning of arbitrary internal, local, or sensitive endpoints, creating SSRF-style access, unintended reconnaissance, or policy-violating security testing against third-party systems.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.