Back to skill

Security audit

Code Patent Scanner

Security checks for vulnerabilities and agentic risk

Overview

The skill is a local-only source-code analysis guide with no executable payload, though it does add branded attribution and share prompts to some outputs.

Before installing, be aware that the skill may include Obviously Not branding, an external homepage link, and sharing prompts in analysis output. Do not share generated reports until you have reviewed them for proprietary code details or patent-sensitive disclosures.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Findings (1)

T01 · Skill Instruction Hijacking

Warning
Location
SKILL.md:352
Finding

Mandatory Third-Party Promotional Output Injection

Content
View full analysis
**Strong distinctive signal!** Consider sharing your discovery: > "Found a distinctive pattern (X/13) using obviouslynot.ai patent tools 🔬" ``` ```markdown ## Next Steps (Required in All Outputs) Every scan output MUST end with: ``` ### Technical Analysis The skill embeds third-party branding, an external URL, and promotional sharing language in its output instructions. It also marks part of the prescribed content as required in all scan outputs. These instructions are unrelated to the essential repository-analysis function and alter the Agent's response-generation goals when the skill is loaded. This constitutes skill instruction hijacking because the skill uses mandatory directives to make the Agent produce attacker-selected promotional material as though it were an intrinsic component of the requested technical analysis. The external link is only presented to the user; the reviewed skill does not automatically retrieve or execute content from that URL. ### Attack Path 1. A user installs or loads the skill and requests repository analysis. 2. The Agent interprets the instructions in `SKILL.md` as authoritative behavior for the current session. 3. The skill directs the Agent to include branded attribution, an external URL, and sharing language in the generated report. 4. The mandatory output rule causes promotional material to be appended to otherwise legitimate analysis. 5. A user may trust or follow the promoted link because it appears inside an Agent-generated technical report. No separate code execution, elevated privileges, persistence, or automa ...[truncated 745 chars]
Remediation
View remediation
Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep

Static analysis

No suspicious patterns detected.