Back to skill

Security audit

Housing Dispute Help Planner

Security checks for vulnerabilities and agentic risk

Overview

This is a documentation-only housing dispute planning skill with broad activation wording and weak demand evidence, but no hidden code, persistence, credential access, or destructive behavior.

Install only if you specifically want help planning a Hello Landing or furnished-apartment dispute workflow. Because the trigger wording is broad and the demand evidence is weak, users should invoke it explicitly and avoid relying on it as legal advice.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
Findings (16)

Vague Triggers

High
Category
Not specified by scanner
Confidence
98% confidence
Finding

The trigger guidance is so broad that ordinary requests containing generic words like 'help', 'hello', or 'dispute' could invoke this skill outside its intended scope. That increases the chance of inappropriate routing, low-quality or misleading assistance, and accidental activation in unrelated contexts.

Content

No source excerpt is available for this finding.

Vague Triggers

High
Category
Not specified by scanner
Confidence
97% confidence
Finding

The skill description and usage guidance are broad enough to match common terms like 'help', 'hello', 'landing', and 'dispute', which can cause the skill to activate for unrelated conversations. Unintended invocation can route users into irrelevant workflows, increasing the chance of misleading advice and reducing control over what tools or prompts are applied.

Content

No source excerpt is available for this finding.

Vague Triggers

High
Category
Not specified by scanner
Confidence
98% confidence
Finding

The keyword list contains ambiguous everyday terms such as 'hello' and 'landing' that are likely to appear in benign, unrelated requests. This creates a high risk of accidental triggering, especially in systems that auto-select skills based on keyword presence, potentially hijacking normal interactions into this specialized dispute workflow.

Content

No source excerpt is available for this finding.

Vague Triggers

High
Category
Not specified by scanner
Confidence
98% confidence
Finding

The skill description includes very broad trigger terms such as "general-help", "hello", and "landing", which are common in ordinary conversations and unrelated requests. This can cause unintended invocation of the skill, leading the agent to route users into dispute-handling workflows when they did not request them, increasing the chance of irrelevant guidance, privacy oversharing, or task hijacking.

Content

No source excerpt is available for this finding.

Vague Triggers

High
Category
Not specified by scanner
Confidence
98% confidence
Finding

The explicit trigger section repeats the same problem by listing unconstrained keywords and example invocations that match highly generic words. Because activation logic lacks boundaries, exclusions, or contextual requirements, normal user text containing words like "hello" or "general-help" may spuriously activate this specialized skill.

Content

No source excerpt is available for this finding.

Vague Triggers

High
Category
Not specified by scanner
Confidence
97% confidence
Finding

The trigger phrase 'Help me People repeatedly need a practical, repeatable way to handle Hello Landing Dispute - Furnished Apartments.' is overly broad because it begins with common conversational language likely to appear in unrelated user prompts. In an agent environment, broad activation increases the chance this skill is invoked accidentally, leading to inappropriate routing, irrelevant advice, and possible exposure of users to unsuitable dispute guidance outside the intended context.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

The invocation section lacks clear boundaries on when the skill should and should not be used, and it provides no negative examples to prevent accidental matching. In this context, the evidence list is also largely unrelated to the stated requirement, making broad invocation guidance more dangerous because it can legitimize misapplication of the skill to arbitrary help requests.

Content

No source excerpt is available for this finding.

Intent-Code Divergence

Medium
Category
Not specified by scanner
Confidence
98% confidence
Finding

The README claims validated demand for a housing-dispute assistance skill, but the cited evidence is largely unrelated programming and computer-support content, with only one apparently relevant Hello Landing dispute link. This is dangerous because it misrepresents the skill’s justification and can cause inappropriate activation, user trust erosion, and downstream reliance on a workflow that was not actually validated for the stated use case.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The trigger keywords and example phrases are overly generic, including terms like 'general-help', 'hello', and 'dispute', which are common in ordinary conversations. This can cause the skill to activate outside its intended scope, leading to irrelevant guidance, prompt-routing collisions, or accidental interception of unrelated user requests.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

The example triggers use generic formulations like 'Help me' and 'I need a practical workflow' without boundaries that distinguish this skill from general assistance requests. In a trigger-driven environment, such examples encourage overly permissive matching logic and make accidental invocation more likely.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The default prompt contains a very broad activation phrase tied to generic terms like "help me" and a long natural-language requirement, which can cause the skill to be invoked in contexts beyond the intended housing-dispute use case. This increases the chance of accidental routing, prompt confusion, or unauthorized use of the skill when user intent is only loosely related.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

Enabling implicit invocation without concrete activation constraints allows the platform to call this skill based on weak semantic matches rather than explicit user intent. Because the skill is framed around broad "general-help" and workflow support, this raises the risk of unintended invocation, data leakage into the skill context, or inappropriate guidance being injected into unrelated conversations.

Content

No source excerpt is available for this finding.

Intent-Code Divergence

Medium
Category
Not specified by scanner
Confidence
98% confidence
Finding

The scoring rationale states strong corroboration, source diversity, and professional/community signal, but the actual evidence shown does not support those conclusions for the housing-dispute topic. Inflated or internally inconsistent scoring can improperly elevate the skill's priority or legitimacy, causing downstream systems or users to rely on an unvetted capability.

Content

No source excerpt is available for this finding.

Intent-Code Divergence

Medium
Category
Not specified by scanner
Confidence
99% confidence
Finding

The evidence section claims to validate demand for a housing-dispute skill, but nearly all cited sources are unrelated technical posts about Rust, R, C++, URI schemes, and Windows/media tooling. This creates a misleading provenance trail and can cause the agent or reviewers to trust and route users to a skill based on fabricated or irrelevant support, undermining integrity of skill selection and decision-making.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

The activation guidance mixes broad keywords like 'general-help', 'hello', and 'landing' with vague trigger sentences, making the skill eligible for many unrelated requests. This ambiguity is more dangerous in a general-help context because the skill can be spuriously selected in ordinary conversations, degrading routing quality and potentially displacing a more appropriate skill.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
84% confidence
Finding

The file labels separate English and Simplified Chinese documents, but this specific README is a zh-CN localized variant and does not state that users may choose their preferred language. Under the policy, locale constraints should be opt-in or clearly justified.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.