Back to skill

Security audit

Error Message Improver

Security checks for vulnerabilities and agentic risk

Overview

This is a documentation-only skill for improving error messages; its main issue is broad implicit activation, not hidden or privileged behavior.

Install only if you want an error-message improvement helper. Be aware that its trigger metadata is broad and implicit invocation is enabled, so it may activate for general debugging or support requests unless the host routes skills carefully.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (12)

Vague Triggers

High
Category
Not specified by scanner
Confidence
98% confidence
Finding

The trigger sentence is written in broad, natural language that could match many ordinary user requests unrelated to this specific skill. In agent-routing systems, overly generic activation phrases can cause unintended invocation, leading the agent to apply the wrong workflow, leak contextual data into an unnecessary skill, or interfere with safer skill selection.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The trigger phrases are broad, natural-language prompts that can activate the skill in situations well beyond a narrowly scoped error-message task. In an agent ecosystem, this increases the chance of accidental or opportunistic invocation, causing the skill to intercept unrelated requests and influence outputs where it was not intended to run.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The trigger phrases are broad enough to match common support or productivity requests, which can cause the skill to activate outside its intended scope. In an agent environment, overbroad activation can steer unrelated conversations into this workflow unexpectedly, creating prompt-scope confusion and increasing the chance of unintended instruction injection or workflow hijacking.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
84% confidence
Finding

The file presents separate English and Chinese documentation variants, and this file itself is a Chinese-language README, but it does not state that language selection is optional or user-driven. Under the policy, language constraints should be offered as a choice or clearly justified rather than implicitly imposed.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

The manifest description uses very broad routing language such as 'Use when a user asks for work-productivity, error messages, debugging, user feedback, support' plus generic artifact requests. This can cause the skill to be invoked for many ordinary requests outside its narrow purpose, increasing the chance of unintended activation, prompt-surface expansion, and interference with more appropriate skills.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
98% confidence
Finding

The trigger keywords are highly generic ('debugging', 'support', 'user feedback', 'troubleshooting') and are not paired with constraints that limit activation to error-message work. In a routing system, such generic triggers can over-match unrelated conversations, causing misrouting and exposing the model to instructions or contexts the skill was not designed to handle.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

The skill description says it should be used for a wide set of categories and for any practical workflow, artifact, checklist, analysis, or implementation support related to the requirement. That scope is so broad that it creates routing ambiguity and increases the chance of unintended invocation, which can mis-handle user requests and expand the skill's effective authority beyond its narrow purpose.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The trigger section uses broad generic keywords such as work-productivity, debugging, support, and troubleshooting, which are common in ordinary conversations. This can cause the skill to activate outside its intended scope, steering unrelated interactions into this workflow and potentially overriding more appropriate skills or user intent.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The default prompt is phrased broadly around common support and productivity concepts, which increases the chance of accidental or overly eager activation during ordinary conversation. In combination with agent routing, this can cause the skill to be invoked when the user did not explicitly request it, potentially exposing user content to an unnecessary processing path or causing confusing, unintended behavior.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

Enabling implicit invocation without strong trigger constraints allows the skill to activate based on loose semantic matches rather than deliberate user selection. Because this skill targets broad topics like debugging, support, feedback, and workflows, the activation surface is especially large, making accidental invocation more likely and increasing the risk of unintended processing of user inputs.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

The invocation guidance uses generic phrasing ('I need a practical workflow...') that is not sufficiently unique to this skill’s purpose. This increases the chance of accidental activation for unrelated productivity requests, which can degrade agent reliability and create opportunities for prompt-routing abuse or incorrect handling of user intent.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
82% confidence
Finding

正文说明和工作流整体以中文编写,文件名也表明这是 zh-CN 版本,但内容中没有说明应根据用户偏好切换语言,或提示这是可选语言版本。若该技能在更广泛环境中被自动选用,可能构成未经用户选择的语言/locale 约束。

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.