Back to skill

Security audit

Llm Api Provider Integration Helper

Security checks for vulnerabilities and agentic risk

Overview

This is a non-executable helper skill for planning MiniMax Response API support, with only a minor risk of being invoked too broadly.

This skill is reasonable to install if you want help planning or implementing MiniMax Provider Response API support. Be aware that its trigger words are broad, so you may want to invoke it explicitly or tighten its activation text if unrelated API/support conversations should not use it.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (5)

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The description says to use the skill for broad categories like 'software-and-data', 'enhancement', 'feature', 'request', and 'support', which do not clearly limit activation to the MiniMax Response API feature request. Ambiguous activation criteria increase the chance of misapplication, causing the wrong skill to handle user requests and potentially producing irrelevant, misleading, or unsafe assistance.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

The trigger list is overly broad and includes generic terms like 'support', 'request', 'response', and 'api', which can match many unrelated user prompts. This can cause the skill to activate outside its intended scope, leading to incorrect routing, unintended disclosure of internal guidance, or disruption of safer/more relevant workflows.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The default prompt is broad and includes generic terms like feature request, support, workflow, checklist, and analysis, which can match many ordinary user requests unrelated to this specific MiniMax Response API integration task. In systems with automatic routing, this can cause the skill to be invoked unexpectedly, exposing users to irrelevant instructions, prompt interference, or unintended handling paths.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

Enabling implicit invocation without clear trigger constraints allows the platform to auto-select this skill based on loose semantic similarity rather than explicit user intent. Because the skill description and prompt are broad, this increases the chance of accidental invocation and cross-context prompt injection or misrouting in normal conversations.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The trigger phrase is overly broad and uses common help-seeking language, which can cause the skill to activate in situations beyond the narrowly intended MiniMax Response API feature-request context. In an agent environment, unintended invocation can route unrelated user requests into this skill, producing irrelevant guidance, mis-scoped actions, or workflow confusion that undermines least-privilege skill selection.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.