Back to skill

Security audit

Error Message Improver

Security checks for vulnerabilities and agentic risk

Overview

This skill is a simple error-message improvement helper with no hidden execution, persistence, credential access, or destructive behavior, though its trigger wording is overly broad.

Installers should be aware that the skill may be invoked by ordinary wording because its keywords are broad and implicit invocation is enabled. For safer routing, prefer explicit use of $error-message-improver or narrow the trigger terms to phrases like better error messages or improve application error copy.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (10)

Vague Triggers

High
Category
Not specified by scanner
Confidence
98% confidence
Finding

The keyword list includes extremely common terms such as 'better', 'error', 'messages', 'level', 'beginner', and 'type', which are likely to appear in many unrelated prompts. This makes accidental or attacker-induced invocation much more likely, potentially hijacking task routing and degrading correctness or safety by steering the agent into an irrelevant skill.

Content

No source excerpt is available for this finding.

Vague Triggers

High
Category
Not specified by scanner
Confidence
98% confidence
Finding

The skill description includes very broad trigger terms such as 'general-help', 'better', 'error', 'messages', and 'labels', which are common in ordinary user conversations and are not tightly bound to this specific requirement. This can cause unintended invocation or routing of unrelated requests into this skill, increasing the chance that the agent follows the wrong workflow and produces misleading or inappropriate output.

Content

No source excerpt is available for this finding.

Vague Triggers

High
Category
Not specified by scanner
Confidence
99% confidence
Finding

The explicit keyword trigger list is too generic and includes standalone words that appear frequently in normal conversation, making accidental activation highly likely. In an agent environment, overly broad triggers can be exploited through prompt wording to steer execution toward this skill even when the user's intent is unrelated, degrading routing integrity and potentially interfering with safer or more appropriate skills.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The trigger phrase is broad enough to match ordinary user requests for help with better error messages, which can cause the skill to activate in situations beyond its narrowly intended scope. Overly broad activation increases the chance of misrouting user requests, unintended instruction injection into unrelated workflows, or unnecessary invocation of skill-specific guidance in general conversations.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The trigger phrases are broad and overlap with common user requests such as asking for help, better messages, or labels. This can cause the skill to activate unintentionally and steer unrelated conversations into this workflow, creating prompt-routing confusion and increasing the chance of inappropriate invocation.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

The skill description is broad enough that it may match many ordinary requests containing terms like 'help', 'better', or 'error', causing unintended invocation. Over-broad routing can misapply the skill, produce irrelevant guidance, and create opportunities for prompt-selection abuse where an attacker intentionally triggers this skill in unrelated contexts.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The example trigger phrase 'Help me Better Error Messages.' is ambiguous and closely resembles ordinary conversation rather than a clearly delimited tool invocation. Ambiguous examples normalize weak trigger boundaries, which can contribute to accidental matching and make the skill easier to invoke unintentionally through natural-language prompts.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

The default prompt uses a very broad invocation phrase ('help me Better Error Messages') combined with implicit invocation, which can match ordinary user requests about improving errors or labels. This can cause the skill to be invoked unintentionally, expanding its influence beyond explicit user consent and increasing the chance of prompt-routing abuse or unexpected behavior in unrelated conversations.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The trigger phrases are broad enough to match ordinary user language such as asking for 'better error messages' or general practical help, which can cause the skill to activate outside narrowly intended scenarios. Over-broad activation is dangerous because it increases the chance of inappropriate routing, unexpected behavior, and prompt-surface expansion where unrelated conversations are pulled into this skill unnecessarily.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
88% confidence
Finding

The README describes separate English and Simplified Chinese documentation variants, and this file itself is specifically localized as zh-CN, but it does not indicate that language selection is optional or user-driven. This can be a locale-policy concern if the skill experience defaults to a language without explicit opt-in.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.