Back to skill

Security audit

Software Data Self Improving Developer Helper

Security checks for vulnerabilities and agentic risk

Overview

This is a documentation-style developer workflow skill with no hidden execution behavior; the main caveat is overly broad auto-invocation wording.

Installers should be aware that this skill may activate on general debugging or improvement requests. Prefer explicit invocation when possible, and consider tightening its trigger keywords before publishing broadly.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (11)

Vague Triggers

High
Category
Not specified by scanner
Confidence
96% confidence
Finding

The trigger phrases are broad natural-language requests like 'Help me...' and 'I need a practical workflow...' tied to common software-help wording, which can cause the skill to activate for many ordinary development conversations outside its intended scope. In an agent ecosystem, overbroad activation can route unrelated prompts into this skill, creating unintended behavior, poor isolation, and increased exposure to downstream risky instructions or workflows.

Content

No source excerpt is available for this finding.

Vague Triggers

High
Category
Not specified by scanner
Confidence
98% confidence
Finding

The trigger list includes extremely common words such as "self" and "improving," which can cause the skill to activate for many unrelated prompts. Over-broad invocation increases the chance that the wrong skill is selected, leading to unintended behavior, prompt interference, or inappropriate handling of user requests.

Content

No source excerpt is available for this finding.

Vague Triggers

High
Category
Not specified by scanner
Confidence
98% confidence
Finding

The trigger list includes very broad everyday terms such as "self", "improving", "enable", and "bug fix", which can match many unrelated user prompts and cause unintended activation. This increases the chance the skill injects irrelevant workflow guidance into conversations, leading to misrouting, user confusion, and accidental execution of a skill in contexts where it was not intended.

Content

No source excerpt is available for this finding.

Vague Triggers

High
Category
Not specified by scanner
Confidence
98% confidence
Finding

The trigger sentences are broad, natural-language phrases that overlap with ordinary user requests, which can cause accidental or inappropriate skill invocation. In an agent ecosystem, overbroad routing can lead to the wrong skill handling requests, producing irrelevant actions, unsafe automation, or bypassing more appropriate safeguards.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
97% confidence
Finding

The trigger phrases are broad and generic, including common words like "self," "improving," and bug-fix oriented requests that could match many unrelated conversations. This can cause unintended activation of the skill, leading the agent to inject workflow behavior or instructions in contexts where the user did not explicitly request this skill, which increases the risk of misrouting, prompt interference, and unsafe overreach.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The keyword list includes highly generic tokens such as 'self', 'improving', 'errors', 'enable', and 'bug fix', which are common across benign everyday requests and are not sufficient to distinguish this skill's intended purpose. Such generic activation terms increase the chance of accidental invocation, making the skill easier to trigger in unrelated contexts and weakening safety boundaries between skills.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

The description's activation guidance uses broad language like "help users" and "needs a practical workflow," which is vague enough to match many unrelated scenarios. This weakens routing precision and can cause accidental invocation, especially in environments that rely on descriptive matching for skill selection.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The example triggers repeat long, generic phrasing instead of showing clear edge conditions, which reinforces ambiguous activation patterns. In practice this can train users or selection systems to invoke the skill too broadly, increasing misrouting and unintended overlap with other skills.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
90% confidence
Finding

The enablement condition in the description is vague and mixes broad topic labels with open-ended phrasing like "needs practical workflow, artifact, checklist, analysis, or implementation support," without clear boundaries. In a skill-routing system, this ambiguity can cause over-triggering and overlap with unrelated skills, reducing predictability and making it easier for benign prompts to activate the skill accidentally.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The default prompt contains very broad trigger language such as 'help me' and a long generic problem description, which can overlap with normal user conversation and cause the skill to activate in contexts the user did not specifically intend. In combination with agent-style workflow assistance, this can lead to accidental routing, unexpected prompt injection surface expansion, or unintended execution of this skill instead of a more appropriate one.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

Enabling implicit invocation without clear activation boundaries allows the platform to select this skill based on loose semantic matching rather than explicit user choice. Because the skill targets broad software, data, and self-improving workflow requests, the activation surface is unusually wide, increasing the chance of unintended invocation, privilege confusion, and exposure to adversarial user phrasing.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.