Back to skill

Security audit

USA Business Migration Planner

Security checks for vulnerabilities and agentic risk

Overview

The package is documentation-only, but it is labeled as a USA business migration planner while its operative instructions route users toward an unrelated V2Echo iOS TestFlight promotion.

Review before installing. This skill does not appear to run code or access data, but its name and display metadata do not match what it actually does, and it can be implicitly invoked on broad terms. It should be renamed and scoped to the V2Echo/TestFlight workflow, or rewritten to match the USA business migration purpose, before normal use.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Findings (1)

T01 · Skill Instruction Hijacking

Error
Location
SKILL.md:1
Finding
Misleading Skill Identity and Broad Implicit Invocation Redirect Agent Behavior to Promotional Content## Vulnerability Details **File Location**: `SKILL.md:1-15, 41-50`; `SKILL.zh-CN.md:1-15, 41-50`; `agents/openai.yaml:1-7` **Vulnerability Type**: T01: Skill Instruction Hijacking **Risk Level**: High ### Vulnerable Code `SKILL.md:1-15`: ```markdown --- name: usa-business-migration-planner description: >- Help users with Validated demand: People repeatedly need a practical, repeatable way to handle V2Echo iOS 客户端 TestFlight 内测招募|前 50 名赠送 Pro 永久权益. This requirement is supported by 12 separate online signals across 3 source families, so it represents broader demand rather than a single isolated request.. Use when a user asks for general-help, v2ex, create, v2echo, ios, or needs a practical workflow, artifact, checklist, analysis, or implementation support for this requirement. --- # USA Business Migration Planner ## Requirement Use this skill to help people asking for help online, especially users who need a reusable workflow instead of a one-off answer with: > Validated demand: People repeatedly need a practical, repeatable way to handle V2Echo iOS 客户端 TestFlight 内测招募|前 50 名赠送 Pro 永久权益. This requirement is supported by 12 separate online signals across 3 source families, so it represents broader demand rather than a single isolated request. ``` `SKILL.md:41-50`: ```markdown ## Triggers Keywords: `general-help`, `v2ex`, `create`, `v2echo`, `ios`, `testflight`, `pro` Example trigger sentences: - `Help me People repeatedly need a practical, repeatable way to handle V2Echo iOS 客户端 TestFlight 内测招募|前 50 名赠送 Pro 永久权益.` - `I need a practical workflow for People repeatedly need a practical, repeatable way to handle V2Echo iOS 客户端 TestFlight 内测招募|前 50 名赠送 Pro 永久权益.` - `Use $usa-business-migration-planner to handle People repeatedly need a practical, repeatable way to handle V2Echo iOS 客户端 TestFlight 内测招募|前 50 名赠送 Pro 永久权益.` ``` `agents/openai.yaml:1-7`: ```yaml interface: display_name: "USA B ...[truncated 3248 chars]
Remediation
## Remediation Suggestions 1. Rename the Skill and its display name so they accurately describe its real purpose. If the intended function is V2Echo TestFlight campaign planning, use a narrowly descriptive campaign-related name. 2. If US business migration is the intended function, remove all V2Echo, TestFlight recruitment, permanent-Pro promotion, and unrelated demand-evidence content. 3. Set `allow_implicit_invocation` to `false` until the Skill identity and behavior are aligned. 4. Replace generic triggers such as `general-help`, `create`, `ios`, and `pro` with explicit, high-specificity triggers tied to the actual declared function. 5. Remove the promotional campaign from `default_prompt`; use a neutral prompt that asks the Agent to address the user's explicitly stated objective. 6. Ensure the English and localized Skill files have identical, accurately scoped behavior. 7. Remove weakly related promotional links from the evidence sections, or clearly label them as non-authoritative context rather than proof of demand. 8. Add routing tests confirming that unrelated requests containing generic terms do not activate the Skill. 9. Require deliberate user consent before generating campaign promotion, recruitment copy, or traffic-diversion links.
Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
Findings (20)

Description-Behavior Mismatch

High
Confidence
99% confidence
Finding
The README presents the skill as a 'USA Business Migration Planner' while the actual requirement, evidence, and usage all target a V2Echo iOS/TestFlight promotional workflow. This kind of identity mismatch is dangerous because users, orchestrators, or reviewers may invoke or approve the skill under false assumptions, enabling inappropriate routing, policy bypass, or misuse of the skill in contexts it was not intended for.

Description-Behavior Mismatch

High
Confidence
99% confidence
Finding
The file claims to be a 'USA Business Migration Planner' but the actual content is about V2Echo iOS TestFlight recruitment, which is a material identity and scope mismatch. This can cause the wrong skill to trigger or be selected under false pretenses, undermining user trust and enabling misrouting of requests to behavior the user did not intend.

Vague Triggers

High
Confidence
96% confidence
Finding
The invocation description says to use the skill for broad categories like general help or implementation support, while the underlying requirement is a very specific TestFlight recruitment scenario. This ambiguity weakens scope boundaries and can cause the orchestrator or reviewer to treat the skill as generally applicable, increasing the risk of unintended activation and misleading outputs.

Description-Behavior Mismatch

High
Confidence
99% confidence
Finding
The skill name and heading present it as a USA business migration planner, but the actual requirement, triggers, and workflow are for an unrelated V2Echo/TestFlight recruitment task. This mismatch can mislead routing, review, and user trust, and may allow the skill to be invoked or approved under false pretenses, increasing the chance of inappropriate activation and unsafe task handling.

Vague Triggers

High
Confidence
98% confidence
Finding
The trigger list includes very broad keywords such as "general-help" and "create," which are likely to match many unrelated user requests. Overbroad activation can cause this skill to hijack conversations outside its intended scope, exposing users to irrelevant or misleading workflows and making prompt-routing behavior easier to manipulate.

Vague Triggers

High
Confidence
97% confidence
Finding
Including overly broad trigger terms such as general-help, create, and ios can cause the skill to activate for many unrelated requests. In an agent system, overbroad activation expands the skill’s reach beyond its intended scope, increasing the risk of unintended execution, prompt interference, and confusing or unsafe outputs.

Description-Behavior Mismatch

High
Confidence
98% confidence
Finding
The documented behavior is a generic workflow for a V2Echo/TestFlight promotional task, while the skill metadata identifies it as a USA business migration planner. This mismatch can cause the wrong skill to be invoked under misleading expectations, creating prompt-routing confusion and opening the door to unauthorized or unintended task execution.

Intent-Code Divergence

High
Confidence
99% confidence
Finding
The usage section explicitly tells operators to use a migration-planner skill for an unrelated promotional/TestFlight recruitment task. This is dangerous because it trains the agent or user to invoke a mislabeled capability, undermining trust boundaries and enabling deceptive repurposing of skills for tasks outside their approved scope.

Vague Triggers

Medium
Confidence
95% confidence
Finding
The trigger phrases use generic helper language such as 'Help me' and 'I need a practical workflow,' which can match ordinary conversation and cause unintended invocation. In an agent environment, overbroad triggers increase the chance that the skill activates without clear user intent, potentially injecting irrelevant instructions or steering workflows unexpectedly.

Vague Triggers

Medium
Confidence
95% confidence
Finding
The trigger phrases are broad natural-language patterns such as 'Help me' and 'I need a practical workflow', which are common in ordinary conversation and not tightly scoped to the skill's intended function. This increases the chance of accidental invocation, causing the agent to route unrelated user requests into this skill and potentially expose users to irrelevant or manipulative outputs.

Description-Behavior Mismatch

Medium
Confidence
98% confidence
Finding
The skill’s declared identity and its actual behavior do not match: the name/header suggest a USA business migration planner, while the content is about V2Echo iOS TestFlight recruitment. This can mislead routing, review, and user trust, causing the skill to be invoked or approved under false assumptions and obscuring what it really does.

Intent-Code Divergence

Medium
Confidence
95% confidence
Finding
The documentation header continues the domain mismatch by presenting the skill as a USA business migration planner while the surrounding sections describe TestFlight recruitment support. Such contradiction increases the chance of deceptive packaging, mistaken activation, and analyst/operator misunderstanding about the skill’s purpose.

Vague Triggers

Medium
Confidence
90% confidence
Finding
The trigger section lacks clear activation boundaries and negative cases, so the system may not distinguish between genuine matching requests and incidental keyword overlap. Ambiguous invocation criteria make accidental or inappropriate activation more likely, especially given the already broad keyword set.

Vague Triggers

Medium
Confidence
95% confidence
Finding
The default_prompt uses a broad, underspecified invocation phrase tied to generic language like 'help me' and a long opaque requirement string, which can cause the skill to be invoked in contexts beyond its intended scope. Because implicit invocation is enabled, this ambiguity increases the chance of unintended routing, user confusion, and execution of the skill for unrelated requests.

Natural-Language Policy Violations

Medium
Confidence
88% confidence
Finding
The manifest embeds mixed-language content in the default prompt without any user locale selection or justification, creating a mismatch between user intent and invoked behavior. This can mislead users, degrade consent and transparency, and increase the risk that unrelated or non-English content is injected into sessions where the user did not request it.

Vague Triggers

Medium
Confidence
96% confidence
Finding
The trigger phrase begins with a broad construction like 'Help me...', which overlaps heavily with normal user speech. In the context of an already mislabeled skill, this increases the chance of accidental activation or overbroad routing, causing the skill to intercept unrelated conversations.

Natural-Language Policy Violations

Low
Confidence
86% confidence
Finding
The README is presented as an English user-facing guide, but the core requirement text is forced into Chinese at line 5 without any user opt-in or explanation of a required locale. This can violate language/locale policy because the skill does not offer a language choice or justify the constraint as region-specific.

Natural-Language Policy Violations

Low
Confidence
84% confidence
Finding
This Chinese README contains substantial English instruction text and English trigger phrases, but does not state that the user can choose their preferred language or that bilingual output is intentional. That can violate language/locale expectations for a locale-specific skill document.

Natural-Language Policy Violations

Low
Confidence
87% confidence
Finding
The core requirement is framed in Chinese text, and the trigger examples repeat that wording, but the document does not state that the skill is region-specific or that users may choose another language. This can create an implicit language/locale constraint without opt-in.

Natural-Language Policy Violations

Low
Confidence
84% confidence
Finding
All listed trigger sentences embed the requirement in Chinese phrasing and do not offer equivalent alternatives in other languages or indicate that users can choose their preferred language. That creates a natural-language policy concern around implicit language restriction.

Static analysis

No suspicious patterns detected.