Back to skill

Security audit

USA Business Migration Planner

Security checks for vulnerabilities and agentic risk

Overview

The skill appears non-destructive, but its purpose, evidence, and automatic trigger scope are too inconsistent and broad to install without review.

Treat this as a review-needed skill: it does not show malware-like behavior, but its automatic routing is too broad and its stated purpose is poorly supported. Install only if you intend to invoke it explicitly, or ask the publisher to narrow triggers, disable implicit invocation, and replace the mismatched evidence and title with a coherent supported use case.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
Findings (17)

Vague Triggers

High
Category
Not specified by scanner
Confidence
98% confidence
Finding

The skill description is broad, repetitive, and includes generic operational terms that could match many normal user requests unrelated to the intended niche use case. This increases the chance of unintended invocation, causing the agent to route users into an irrelevant workflow and potentially override better-scoped skills or normal handling.

Content

No source excerpt is available for this finding.

Vague Triggers

High
Category
Not specified by scanner
Confidence
99% confidence
Finding

The trigger keywords include extremely generic terms such as 'option', 'menu', 'links', and 'displayed', which are common in everyday conversation and unrelated tasks. Such low-specificity triggers can cause frequent accidental activation, making prompt routing unreliable and creating opportunities for skill hijacking through incidental wording.

Content

No source excerpt is available for this finding.

Vague Triggers

High
Category
Not specified by scanner
Confidence
93% confidence
Finding

The invocation description is broad and ambiguous, describing use for general requests involving workflows, checklists, analysis, or implementation support tied to loosely defined terms. Because activation boundaries are unclear, the skill may be selected for many unrelated requests, leading to misrouting, prompt confusion, and unsafe task capture by a mismatched skill.

Content

No source excerpt is available for this finding.

Vague Triggers

High
Category
Not specified by scanner
Confidence
96% confidence
Finding

The trigger keywords include very generic terms like "option", "menu", "links", and "displayed", which are common in ordinary user requests and can cause accidental activation outside the intended business-migration use case. This creates prompt-scope confusion and increases the chance the skill intercepts unrelated conversations, producing unintended behavior or overriding more appropriate skills.

Content

No source excerpt is available for this finding.

Intent-Code Divergence

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The README asserts that the requirement is validated by 12 signals, but the cited links appear unrelated to the claimed 'USA Business Migration Planner' workflow and the specific 'Waffle menu or links displayed normally' requirement. This can mislead users or downstream systems into trusting the skill's legitimacy and applicability based on fabricated or mismatched evidence, increasing the risk of inappropriate use or deployment.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The trigger phrases and keywords are broad, vague, and include generic terms such as 'option', 'menu', and 'links', which can cause accidental or overly permissive invocation. In an agent ecosystem, ambiguous activation increases the chance that the wrong skill is selected for unrelated requests, potentially leading to misleading guidance, context leakage between tasks, or unsafe automation paths.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

The README claims to be a USA business migration planner, but the stated demand, evidence links, and described workflow are unrelated and appear mismatched. This kind of scope/identity inconsistency can mislead users and routing systems into invoking the skill for the wrong tasks, which is dangerous in agent environments because users may disclose irrelevant sensitive business context or rely on an unfit workflow.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The trigger phrases are broad and generic enough to match common everyday requests, increasing the chance of accidental activation. In an agent skill ecosystem, overbroad activation can cause the wrong skill to take over user interactions, producing misleading guidance, collecting unnecessary context, or interfering with safer/more relevant skills.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The example trigger sentences model invocation patterns that are themselves vague and self-referential, reinforcing activation on broad natural-language phrasing rather than clear boundaries. This teaches the router to associate the skill with generic help requests, further increasing accidental or adversarial invocation.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
87% confidence
Finding

Although the file is a zh-CN skill document, substantial user-facing content and trigger examples are written in English, and there is no indication that the user can choose their preferred language. This can effectively impose a language format on users without opt-in, which matches the language/locale policy concern.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

The default prompt is vague and overly broad, describing use cases in a way that can cause the platform to invoke this skill for loosely related business or workflow requests. Because the prompt also includes awkward, catch-all phrasing, it increases the risk of misrouting user requests and exposing users to incorrect automation or unintended skill activation.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
97% confidence
Finding

Implicit invocation is enabled even though the manifest provides no narrow trigger constraints, making it easier for the system to call this skill based on weak semantic matches. In this skill, the metadata is broad and noisy enough that unrelated user requests about business operations, menus, links, or implementation help could trigger it unexpectedly.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

The trigger sentences are built around broad, generic language such as 'help me' and 'I need a practical workflow,' which can cause the skill to activate for many unrelated requests. In an agent environment, overly broad triggers increase the chance of accidental invocation, context hijacking, or routing user requests into an irrelevant skill that then shapes the response incorrectly.

Content

No source excerpt is available for this finding.

Intent-Code Divergence

Low
Category
Not specified by scanner
Confidence
74% confidence
Finding

The text asserts operational behavior such as transforming requests, producing deliverables, and checking results, but in the provided file there is no implementation or executable logic—only descriptive content. That creates an intent/documentation divergence within the artifact being analyzed.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
81% confidence
Finding

The phrase 'English Codex-valid skill instructions' indicates an English-specific constraint in the skill documentation. In this file, that language requirement is not presented as an optional user choice or as a clearly justified regional/compliance limitation.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
78% confidence
Finding

This file is entirely presented as a Chinese-language README variant, but it does not explicitly offer user language choice or explain any locale restriction within the document itself. Under the policy, forcing a specific language without opt-in can be a natural-language policy concern unless the locale constraint is documented and justified.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
80% confidence
Finding

The skill is labeled and prompted specifically as 'USA Business Migration Planner,' which imposes a locale-specific framing, but the manifest does not indicate that users can opt into this locale or that the restriction is intentional and justified. Under the policy, locale-specific constraints should either be optional for the user or clearly documented as necessary.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.