Back to skill

Security audit

Customer Complaint 8D Report

Security checks for vulnerabilities and agentic risk

Overview

This skill is a straightforward 8D report drafting template with some broad triggers, but no hidden execution, credential access, persistence, or external data movement.

Install this if you want help drafting 8D/CAR quality reports. Be aware that broad triggers may make it appear during general quality discussions, and review any report content before sharing it with customers because the skill uses placeholders and user-provided facts rather than verified data.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (4)

Shadow Command Trigger

Medium
Category
Trigger Abuse
Confidence
89% confidence
Finding

The trigger 'write 8D' overlaps with a generic authoring verb and may conflict with built-in 'write' behaviors or other writing-related skills. This creates a shadow-command risk where users intending a general writing action are unexpectedly routed into this skill, potentially disrupting workflows and producing incorrect outputs.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

The trigger list contains generic quality-management phrases such as 'root cause analysis', 'containment action', and 'corrective action report' that can match many unrelated requests. This can cause the skill to activate outside its intended scope, leading to prompt hijacking of normal workflows, incorrect routing, or unintended use of this template-driven behavior when a different tool or process was expected.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

The phrase 'when the user says they are writing the report for that customer' does not define a specific trigger or boundary for activation. This could cause unintended invocation because merely mentioning a customer in normal conversation may be interpreted as selecting a format, without an explicit command or exclusion conditions.

Content

No source excerpt is available for this finding.

Overly Broad Trigger

Low
Category
Trigger Abuse
Confidence
97% confidence
Finding

The standalone trigger '8D' is extremely short and ambiguous, making accidental invocation likely in normal manufacturing or quality discussions. While it does not directly enable code execution or data exfiltration, it can misroute user intent and cause the wrong skill to take control of a conversation.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.