Back to skill

Security audit

USA Business Migration Planner

Security checks for vulnerabilities and agentic risk

Overview

The package appears non-executable, but its public name and routing describe U.S. business migration while the actual skill content is a Cambridge-versus-Amazon career decision workflow with broad implicit activation.

Review before installing. The skill does not appear to run code or access sensitive data, but its name and automatic invocation policy are misleading and overly broad. Install only if you specifically want a Cambridge CS master's versus Amazon new-grad decision-support skill, and prefer renaming it and narrowing triggers or disabling implicit invocation first.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
Findings (20)

Vague Triggers

High
Confidence
97% confidence
Finding
The trigger description is broad enough to match many ordinary requests for workflow, checklist, analysis, or implementation help, even when unrelated to the intended task. Overbroad activation can route unrelated conversations into this skill, causing prompt hijacking of task selection, user confusion, and unreliable or irrelevant outputs.

Vague Triggers

High
Confidence
99% confidence
Finding
Keywords such as 'start,' 'masters,' 'grad,' and 'amazon' are common in everyday conversation and are likely to collide with benign requests. This makes accidental invocation highly likely, which can let the skill inappropriately influence responses outside its domain.

Description-Behavior Mismatch

High
Confidence
99% confidence
Finding
The skill’s name and framing claim it is for USA business migration planning, but the actual body is about choosing between a Cambridge CS master’s and an Amazon new-grad role. This semantic mismatch can cause the wrong skill to be invoked, mislead operators reviewing capabilities, and bypass user expectations or policy routing based on the declared purpose.

Vague Triggers

High
Confidence
97% confidence
Finding
The trigger keywords include very broad terms such as 'start', 'grad', and 'amazon', which are likely to overlap with ordinary conversation. Overbroad triggers can cause frequent unintended activation, injecting irrelevant workflows or hidden instructions into unrelated tasks and degrading trust and control over skill execution.

Vague Triggers

High
Confidence
98% confidence
Finding
The skill allows implicit invocation and uses very broad trigger terms in its metadata such as work-productivity, analysis, checklist, and implementation support. That ambiguity increases the chance the agent will auto-select this skill for unrelated requests, exposing user inputs to an ill-scoped tool and producing confusing or manipulative outputs without clear user intent.

Vague Triggers

High
Confidence
98% confidence
Finding
The trigger sentence uses a broad everyday phrase ('Help me ...') tied to an incomplete, generic request pattern, which can match many unrelated user prompts. In an agentic environment, overbroad triggers can cause silent skill hijacking, where this skill is selected for conversations outside its intended purpose and influences outputs with irrelevant or misleading workflow guidance.

Description-Behavior Mismatch

Medium
Confidence
98% confidence
Finding
The README presents the skill as a 'USA Business Migration Planner' while the actual documented function is a Cambridge-vs-Amazon career decision workflow. This kind of identity/scope mismatch can mislead routing, approval, or user trust decisions, causing the skill to be invoked in the wrong context or bypass appropriate review for its real purpose.

Vague Triggers

Medium
Confidence
93% confidence
Finding
The invocation guidance is underspecified and overly broad, listing generic keywords and open-ended phrases without clear scope boundaries. In a skill-selection system, this can lead to unintended activation, misrouting of user requests, and interference with other skills handling unrelated productivity or education queries.

Vague Triggers

Medium
Confidence
97% confidence
Finding
The trigger sentence is phrased so broadly and unnaturally that it lacks meaningful activation constraints, increasing the chance of accidental or irrelevant invocation. Overbroad triggers can cause prompt/skill hijacking at the orchestration layer by matching benign user text that was not intended to call this skill.

Vague Triggers

Medium
Confidence
98% confidence
Finding
The trigger phrases are broad, generic, and partially malformed, making it plausible that ordinary user requests could unintentionally activate this skill outside its intended scope. In an agent system, over-broad activation can route unrelated conversations into this skill, causing misleading guidance, unintended tool use, or policy bypass through incorrect skill selection.

Description-Behavior Mismatch

Medium
Confidence
98% confidence
Finding
The skill name and manifest present a 'USA Business Migration Planner,' but the body describes an unrelated decision aid about choosing between a Cambridge CS master's and an Amazon new-grad job. This semantic mismatch can cause incorrect skill selection, confuse users and downstream agents, and increase the chance the wrong workflow is invoked for a request.

Vague Triggers

Medium
Confidence
91% confidence
Finding
The example trigger phrases use everyday wording like 'Help me' and 'I need a practical workflow,' which normalizes broad matching behavior and encourages accidental activation. While examples are not executable code, they shape implementation and can widen the effective trigger surface of the skill.

Natural-Language Policy Violations

Medium
Confidence
86% confidence
Finding
该技能文件为 `SKILL.zh-CN.md`,正文与触发说明均固定为中文,没有看到向用户提供语言/地区选择或显式说明仅适用于特定中文用户场景。根据规则,若技能强制特定语言而无用户选择或正当约束说明,属于自然语言策略问题。

Vague Triggers

Medium
Confidence
90% confidence
Finding
The enablement condition in the description is vague and expansive, covering generic requests for workflow, analysis, checklist, or implementation support. This ambiguity broadens the activation surface and makes it difficult to predict when the skill should or should not run, increasing the risk of inappropriate invocation.

Intent-Code Divergence

Medium
Confidence
96% confidence
Finding
The top-level title says 'USA Business Migration Planner' while the workflow and examples clearly target an education/career decision. Such contradictions increase the chance of accidental activation, operator confusion, and misapplication of the skill in contexts where different safeguards or domain assumptions should apply.

Description-Behavior Mismatch

Medium
Confidence
98% confidence
Finding
The manifest presents the skill as a USA business migration planner, but the embedded description and prompt describe an unrelated Cambridge-vs-Amazon career decision workflow. This mismatch can mislead users and the orchestrator into invoking the wrong capability, causing unintended disclosure of user context or generation of irrelevant guidance under false pretenses.

Natural-Language Policy Violations

Medium
Confidence
88% confidence
Finding
The skill branding hard-codes a U.S.-specific business migration framing even though the actual content concerns a UK education-versus-U.S. employment decision. This can bias routing and recommendations toward a locale the user did not request, creating misleading advice and potentially mishandling jurisdiction-sensitive guidance.

Description-Behavior Mismatch

Medium
Confidence
98% confidence
Finding
The skill name and declared purpose imply USA business migration planning, but the actual content is a generic career/education decision aid about Cambridge versus Amazon. This mismatch can cause the agent to invoke the skill in unrelated contexts, misleading users and other system components about what the skill does and increasing the chance of inappropriate activation or unsafe reliance on irrelevant guidance.

Vague Triggers

Medium
Confidence
94% confidence
Finding
The activation examples are ambiguous, truncated, and do not clearly define when the skill should or should not run. Ambiguous trigger scope increases the risk of accidental invocation, especially because the rest of the file already frames the skill as a reusable generic workflow rather than a tightly bounded specialized capability.

Natural-Language Policy Violations

Low
Confidence
81% confidence
Finding
This is a Chinese-language README, but the prescribed trigger phrases are presented only in English imperative form. That can amount to a language preference being imposed on users without explicit opt-in or a stated reason for the locale constraint.

Static analysis

No suspicious patterns detected.