Back to skill

Security audit

Error Message Improver

Security checks for vulnerabilities and agentic risk

Overview

This is a documentation-only skill for improving error messages, with broad auto-invocation wording but no hidden code, credential access, persistence, or destructive behavior.

Install only if you want a skill that may be selected for error-message improvement and related support-writing tasks. Its trigger wording is broad, so review or narrow invocation settings if you do not want it activating on general debugging or support requests.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (12)

Vague Triggers

High
Category
Not specified by scanner
Confidence
97% confidence
Finding

The skill description uses very broad activation terms such as work-productivity, debugging, support, and implementation support, which can cause the skill to be invoked for many unrelated requests. Overbroad routing increases the chance that this skill intercepts prompts outside its intended scope, leading to prompt-selection hijacking, degraded safety controls, or inappropriate handling of sensitive tasks.

Content

No source excerpt is available for this finding.

Vague Triggers

High
Category
Not specified by scanner
Confidence
97% confidence
Finding

The trigger keywords are generic and unconstrained, especially terms like debugging, support, troubleshooting, and user feedback. These broad triggers can match a large fraction of ordinary user requests, making accidental or adversarial over-activation more likely and reducing confidence that the selected skill is the safest or most relevant one.

Content

No source excerpt is available for this finding.

Vague Triggers

High
Category
Not specified by scanner
Confidence
98% confidence
Finding

The trigger sentence is so broad and awkwardly templated that it can match ordinary user requests about help, workflows, debugging, or support, causing the skill to activate outside a narrowly intended context. Over-broad activation can route unrelated conversations into this skill, increasing the chance of prompt interception, unintended workflow execution, or contamination of responses with irrelevant instructions.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

The invocation guidance lists broad keywords and example triggers but does not define when the skill should not be used, creating ambiguous routing boundaries. In agent environments, this can lead to accidental invocation on everyday requests about support or debugging, causing prompt hijacking of normal task selection and inappropriate execution paths.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The trigger phrase is extremely broad and maps to common support and productivity requests, which can cause the skill to activate in situations far beyond its intended scope. Over-broad routing can override more appropriate skills or inject generic troubleshooting behavior into unrelated workflows, reducing user control and increasing the chance of unsafe or low-quality handling.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The trigger phrases are broad enough to match common support and productivity requests, which can cause this skill to activate in situations far beyond its intended scope. Over-broad activation increases the chance of unintended instruction injection into unrelated workflows, misrouting user tasks, or causing the agent to privilege this skill when another safer or more specific skill should apply.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
90% confidence
Finding

The example trigger phrases are phrased broadly enough that they normalize invocation from vague, everyday requests rather than clearly scoped error-message tasks. This can train routing behavior toward unnecessary activation, which is less severe than the broad keyword issue but still contributes to misselection and context bleed.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The trigger keywords are very broad and include generic support/debugging terms that can match many unrelated user requests, increasing the chance this skill is invoked when it is not the best fit. Over-broad activation can cause prompt/skill routing confusion, produce irrelevant guidance, and crowd out more appropriate or safer domain-specific skills.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
90% confidence
Finding

The default prompt uses broad everyday phrasing such as helping with work productivity, debugging, feedback, support, workflows, artifacts, and analysis, which functions as an overly general invocation cue. This can cause the orchestration system to match the skill to ordinary conversation topics far beyond error-message rewriting, leading to over-triggering, context leakage, and unintended influence on agent behavior.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

Implicit invocation is enabled, but the skill metadata does not define a narrow or well-scoped trigger condition. Because the skill is framed around broad concepts like productivity, debugging, support, and workflows, the agent may auto-select it in many unrelated contexts, causing unplanned prompt expansion and increasing the chance that user data or conversation context is routed through this skill unnecessarily.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
83% confidence
Finding

Several core usage lines, including the workflow description and trigger phrases, are written in English inside a Chinese-language README. This can amount to an implicit language constraint without user opt-in or a documented justification.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
90% confidence
Finding

该文件整体以 zh-CN 区域语言版本提供,但文档中未说明这是可选本地化展示,亦未向用户提供语言选择或切换方式。按规则,若技能自然语言内容实际上强制特定语言而无用户选择,属于语言/地区策略风险。

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.