Back to skill

Security audit

Local Llm Setup Advisor

Security checks for vulnerabilities and agentic risk

Overview

This is a markdown-only planning skill for a specific llama.cpp endpoint feature request, with no executable code, credential handling, persistence, or hidden data movement observed.

Installers should be aware that the skill may activate for broad feature-request or remote-support language. Prefer explicit use by skill name or narrower trigger phrases if routing precision matters.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (4)

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

The skill description includes very broad trigger terms such as 'work-productivity', 'feature', 'request', 'support', and 'remote', which are common in many unrelated conversations. This can cause unintended invocation of the skill, leading the agent to apply specialized instructions in contexts where they do not belong and increasing the risk of scope confusion or prompt-routing mistakes.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
98% confidence
Finding

The keyword trigger list is overly generic and contains short, everyday terms like 'feature', 'request', 'support', 'remote', and 'server'. In a routing system, these generic keywords can match many benign requests, causing accidental skill activation and misapplication of this skill's workflow to unrelated tasks.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The skill enables implicit invocation while advertising a very broad set of triggers such as 'work-productivity,' 'feature,' 'request,' 'support,' 'workflow,' 'artifact,' 'checklist,' 'analysis,' and 'implementation support.' This can cause the agent to invoke the skill in many unrelated contexts, exposing users to unintended prompt routing, over-collection of context, or manipulation if the skill content later becomes unsafe or overly influential.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

The trigger phrase "Help me [Feature Request] Support for Remote llama.cpp Server via URL Endpoint" is highly generic because it begins with common conversational language ("Help me") and can match ordinary user requests outside the intended narrow skill scope. This can cause unintended activation of the skill, routing unrelated prompts into a specialized workflow and potentially producing misleading or inappropriate output for the user's actual task.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.