Back to skill

Security audit

Stereoscopic 3D Support Helper

Security checks for vulnerabilities and agentic risk

Overview

This is a simple stereoscopic 3D feature-request helper with no executable code, persistence, or credential access.

Before installing, consider narrowing the trigger keywords or relying on explicit invocation so unrelated support or overview requests do not accidentally use this helper.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (11)

Vague Triggers

High
Category
Not specified by scanner
Confidence
97% confidence
Finding

The trigger list includes very broad terms such as 'support', 'overview', 'mode', 'would', 'great', and 'maybe', which are common in ordinary conversation and unrelated requests. This can cause the skill to activate outside its intended stereoscopic-3D context, leading to incorrect routing, prompt-scope confusion, or unintended influence over benign user interactions.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The keyword list includes vague terms like 'support', 'overview', 'mode', 'would', 'great', and 'maybe', which are common in normal conversation and unrelated contexts. Such broad activation criteria can cause accidental invocation of the skill, reducing routing reliability and creating opportunities for inappropriate handling of user requests.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

The trigger sentence is highly generic and can match ordinary user requests rather than a deliberate request to invoke this specific skill. That increases the chance of unintended activation, causing the agent to route unrelated conversations into this workflow and potentially produce irrelevant or misleading operational guidance.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The keyword list contains several broad or generic terms such as 'support', 'overview', 'mode', 'would', 'great', and 'maybe', which make invocation ambiguous. In a skill-routing system, these terms can match many unrelated conversations, causing accidental invocation and reducing reliability of task isolation.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The trigger phrase examples are overly generic help-seeking requests and can cause the skill to activate outside its intended domain. This increases the chance of unintended routing, where unrelated user requests are handled by this skill and receive irrelevant or misleading workflow guidance.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

The description says to use the skill for 'business-and-operations, stereoscopic, support, overview, mode' and for broad needs like 'practical workflow, artifact, checklist, analysis, or implementation support,' but it does not clearly bound the subject matter to stereoscopic-3D requests. This ambiguity increases the chance of overbroad invocation and accidental application to unrelated tasks.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
90% confidence
Finding

The example trigger 'Help me stereoscopic 3d support.' is a highly generic help-style phrase that resembles normal user language and could encourage loose matching behavior. In combination with the broad keyword list, it increases the likelihood of false activations rather than targeted use.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

The skill description defines activation conditions broadly across vague business-and-operations and support-oriented requests without clear boundaries or exclusions. In an agent environment, ambiguous routing criteria increase the chance that this skill is selected for unrelated tasks, which can degrade task isolation and cause users to receive inappropriate guidance or generated modifications outside the intended stereoscopic 3D scope.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
97% confidence
Finding

The trigger keyword list includes very broad, everyday terms such as "support", "overview", "mode", "would", "great", and "maybe". This can cause the skill to activate in unrelated conversations, leading to prompt-routing errors, irrelevant workflow generation, and unintended exposure of the skill’s instructions or outputs in contexts where it was not requested.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The default prompt and skill framing use broad, repetitive language around 'stereoscopic 3d support' without clear invocation boundaries, while implicit invocation is enabled. This can cause the agent to select the skill for loosely related requests, leading to unintended routing, user confusion, or inappropriate operational guidance in contexts that did not explicitly request this helper.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The trigger keyword "would" is extremely broad and likely to appear in many unrelated user requests, which can cause this skill to activate unintentionally. Over-broad invocation increases the chance of routing users into an irrelevant workflow, causing confusion, degraded reliability, and possible interference with more appropriate skills.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.