Back to skill

Security audit

Error Message Improver

Security checks for vulnerabilities and agentic risk

Overview

This markdown-only skill helps improve error messages; its activation wording is broad, but it does not request sensitive access, persistence, or hidden execution.

This skill is reasonable to install for improving user-facing error messages. Be aware that its triggers are broad, so it may activate for general support or debugging requests where a more specific skill or ordinary assistant behavior would be better.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (12)

Vague Triggers

High
Category
Not specified by scanner
Confidence
98% confidence
Finding

The trigger sentence uses highly generic language such as 'Help me' and 'I need a practical workflow,' which overlaps with ordinary user requests across many domains. This can cause unintended activation of the skill outside its intended scope, leading to context hijacking, user confusion, or execution of the wrong workflow when another skill or general assistant behavior should have handled the request.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

The trigger sentences are broad enough to activate on common help requests about debugging, support, and workflows, which can cause the skill to engage outside a narrowly intended scope. Over-broad activation is risky because it can unexpectedly steer user interactions, override more appropriate skills, or collect/process context the user did not specifically intend to route through this skill.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

The trigger phrases are very generic and can match ordinary help requests about productivity, debugging, or support, causing the skill to activate outside its intended scope. Over-broad activation increases the chance of unintended routing, prompt hijacking exposure, or the skill being invoked on unrelated user inputs where it may override more appropriate handling.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
97% confidence
Finding

The skill description is broadly scoped to generic productivity, support, debugging, and implementation-help requests, which can cause over-invocation outside the narrow task of improving error messages. Over-broad routing increases the chance the agent applies this skill in unrelated contexts, creating prompt-scope confusion and potentially displacing safer or more appropriate skills.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The trigger keywords are very generic and map to common user intents such as support, debugging, and troubleshooting without requiring any mention of error-message quality. In a skill-routing system, this can lead to excessive activation frequency, incorrect tool selection, and unintended handling of requests beyond the skill's intended safety and competency boundaries.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
82% confidence
Finding

该文件为 SKILL.zh-CN.md,内容整体以中文呈现,但未见说明这是可选语言版本、也未向用户提供语言选择或切换方式。根据 SQP-3,若技能强制特定语言或地区设置且缺乏用户选择,属于自然语言政策风险。

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

触发关键词如“work-productivity”“support”“debugging”等范围较宽,容易与普通用户请求重叠,导致技能在非目标场景下被误触发。误触发本身不一定直接造成安全破坏,但会让代理在错误上下文中调用该技能,增加信息处理偏差、结果不相关或覆盖更合适技能的风险。

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

示例触发句采用了非常常见的请求表达,如“I need a practical workflow...”,且缺少边界说明,可能被系统当作通用工作流帮助意图而频繁触发该技能。这会放大误路由概率,使代理偏向该技能处理广泛任务,降低结果准确性并干扰其他更适配技能。

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The default prompt is broad and can cause the skill to be invoked for loosely related requests without clear user intent or narrow trigger boundaries. In combination with allow_implicit_invocation: true, this increases the chance of over-triggering, unintended routing, and the skill influencing conversations outside its intended scope.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
75% confidence
Finding

The file specifies separate English and Chinese instruction/readme files, but does not say that the user can choose their preferred language or that language selection is optional. This can create an implicit locale policy without clear opt-in.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
81% confidence
Finding

This Chinese README presents core requirement and audience text in English, which can impose a language choice on users without stating that bilingual content is intentional or optional. That may conflict with language/locale policy expectations when no user opt-in or documented justification is provided.

Content

No source excerpt is available for this finding.

Vague Triggers

Low
Category
Not specified by scanner
Confidence
90% confidence
Finding

The example trigger phrases use broad everyday wording that reinforces permissive matching and encourages invocation on loosely related requests. While not directly dangerous on their own, they train routing behavior toward false positives and can widen the operational scope of the skill beyond error-message improvement.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.