Back to skill

Security audit

Skill Ten Prompt Generator

Security checks for vulnerabilities and agentic risk

Overview

This is a markdown-only prompt-engineering skill bundle whose risky-looking examples are mostly disclosed templates, not hidden code or automatic system access.

Installers should understand that this bundle teaches agents how to write prompts, including prompts for code execution, data analysis, long-running tasks, style imitation, and text humanization. Review automation prompts before using them on sensitive data or external posting workflows, and be careful with the documented deletion commands.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Output HandlingUnvalidated Output Injection, Cross-Context Output, Unbounded Output
  • System Prompt LeakageDirect Leakage, Indirect Extraction, Tool-Based Exfiltration
  • Tool MisuseTool Parameter Abuse, Chaining Abuse, Unsafe Defaults
Findings (47)

Direct Prompt Extraction

High
Category
System Prompt Leakage
Confidence
85% confidence
Finding

Skill contains instructions that could directly expose system prompts, internal rules, or hidden instructions to users or external parties.

Content

Scanner excerpt · .claude/skills/coding-prompt-assistant/skill.md (reported line 168)May include surrounding context.

输出规则模板

text
[Output Rules]
1. You MUST output the FULL content of the file, not just the changes
2. Do NOT use comments like // ... existing code or // ... rest of implementation
3. If the file is too long, stop at a logical break point and ask to continue

Direct Prompt Extraction

High
Category
System Prompt Leakage
Confidence
85% confidence
Finding

Skill contains instructions that could directly expose system prompts, internal rules, or hidden instructions to users or external parties.

Content

Scanner excerpt · .claude/skills/voice-conversation-coach/skill.md (reported line 36)May include surrounding context.

md
You are in a real-time voice conversation.

OUTPUT RULE:
1. NO LISTS - Never use numbered lists or bullet points
2. NO FORMATTING - Do NOT use markdown, bold, or headers
3. LENGTH - Keep responses under 2 sentences unless asked to elaborate

Direct Prompt Extraction

High
Category
System Prompt Leakage
Confidence
85% confidence
Finding

Skill contains instructions that could directly expose system prompts, internal rules, or hidden instructions to users or external parties.

Content

Scanner excerpt · prompt_new.md (reported line 685)May include surrounding context.

md
# 实战模版:

[Output Rules]

1. You must output the FULL content of the file, not just the changes.

Agent Config Directory Access

High
Category
Agent Snooping
Confidence
85% confidence
Finding

Skill reads from agent configuration directories (.claude/, .codex/, .gemini/). These directories may contain API keys, personal settings, and other credentials that the skill has no legitimate need to access.

Content

Scanner excerpt · skills.md (reported line 190)May include surrounding context.

ls .claude/skills/

View a specific Skill's content

cat ~/.claude/skills/my-skill/SKILL.md

text

## 测试 Skill

Tool Parameter Abuse

High
Category
Tool Misuse
Confidence
90% confidence
Finding

Using rm -rf ~/.claude/skills/my-skill in documentation can lead to unintended deletion if users substitute the path incorrectly or invoke automation without confirmation. In an agent ecosystem, recursive force deletion is especially risky because path construction mistakes can silently remove additional files.

Content

Scanner excerpt · skills.md (reported line 322)May include surrounding context.

bash
# Personal
rm -rf ~/.claude/skills/my-skill

# Project
rm -rf .claude/skills/my-skill

Tool Parameter Abuse

High
Category
Tool Misuse
Confidence
90% confidence
Finding

Using rm -rf ~/.claude/skills/my-skill in documentation can lead to unintended deletion if users substitute the path incorrectly or invoke automation without confirmation. In an agent ecosystem, recursive force deletion is especially risky because path construction mistakes can silently remove additional files.

Content

Scanner excerpt · skills.md (reported line 322)May include surrounding context.

bash
# Personal
rm -rf ~/.claude/skills/my-skill

# Project
rm -rf .claude/skills/my-skill

Tool Parameter Abuse

High
Category
Tool Misuse
Confidence
85% confidence
Finding

rm -rf .claude/skills/my-skill recursively and forcibly deletes project files without confirmation. In context this is maintenance guidance, but it still creates a meaningful risk of accidental data loss, especially if automated or run from the wrong working directory.

Content

Scanner excerpt · skills.md (reported line 325)May include surrounding context.

rm -rf ~/.claude/skills/my-skill

Project

rm -rf .claude/skills/my-skill git commit -m "Remove unused Skill"

text

Agent Config Directory Access

High
Category
Agent Snooping
Confidence
85% confidence
Finding

Skill reads from agent configuration directories (.claude/, .codex/, .gemini/). These directories may contain API keys, personal settings, and other credentials that the skill has no legitimate need to access.

Content

Scanner excerpt · skills.md (reported line 413)May include surrounding context.

bash
# View frontmatter
cat .claude/skills/my-skill/SKILL.md | head -n 15

# Check for common issues
# - Missing opening or closing ---

Skill Enumeration

Medium
Category
Agent Snooping
Confidence
85% confidence
Finding

Skill enumerates or reads other installed skills. Access to other skills' SKILL.md files or the skills directory reveals prompt instructions, capabilities, and secrets that should be invisible to peer skills.

Content

Scanner excerpt · .claude/CLAUDE.md (reported line 105)May include surrounding context.

md
## File Conventions

- Each skill has a `skill.md` file with YAML frontmatter (name, description)
- Skills are discovered automatically by Claude Code from `.claude/skills/`
- Descriptions should include trigger keywords for routing
- Use semantic naming (e.g., `camera_movement_type` not `cmt`)

Unbounded Output

Medium
Category
Output Handling
Confidence
60% confidence
Finding

Output size or generation rate is not bounded. Unbounded output enables denial-of-service through resource exhaustion, log flooding, or context-window stuffing.

Content

Scanner excerpt · .claude/skills/coding-prompt-assistant/skill.md (reported line 183)May include surrounding context.

[Output Requirements]

  • Full file content
  • No truncation or省略
  • File path included
text

Unbounded Resource Access

Medium
Category
Excessive Agency
Confidence
75% confidence
Finding

Skill allows unbounded resource consumption (API calls, storage, compute). Without rate limits or quotas, a compromised or misbehaving agent can cause denial-of-service or cost overruns.

Content

Scanner excerpt · .claude/skills/long-running-orchestrator/skill.md (reported line 110)May include surrounding context.

md
If a task fails:
1. Log the error in progress.log
2. Move to next independent task
3. Do NOT retry indefinitely

[TERMINATION]
When all tasks complete, output "ALL TASKS COMPLETE" in progress.log.

Unbounded Resource Access

Medium
Category
Excessive Agency
Confidence
75% confidence
Finding

Skill allows unbounded resource consumption (API calls, storage, compute). Without rate limits or quotas, a compromised or misbehaving agent can cause denial-of-service or cost overruns.

Content

Scanner excerpt · .claude/skills/long-running-orchestrator/skill.md (reported line 193)May include surrounding context.

md
- If you fail 3 times in a row on the same task
   - Write "STUCK: [reason]" to the log
   - Move to the next independent task
   - Do NOT loop indefinitely

[Logging]
All errors must be logged with:

YARA rule 'network_reconnaissance': Network reconnaissance and scanning patterns [hacktools]

Medium
Category
YARA Match
Confidence
65% confidence
Finding

YARA rule matched a hack tool or exploit indicator (offensive tools, reconnaissance, privilege escalation, or exploit frameworks).

Content

Scanner excerpt · .claude/skills/voice-conversation-coach/skill.md (reported line 176)May include surrounding context.

)

  • Result: "How do you know it worked?"

压力追问:

  • "Why that approach?"
  • "What if X happened?"
  • "How would you do it differently?"
text

---

## 技巧4:辩论模式:红队反驳

**适用场景**:辩论练习

**核心原则**:站在对立面,寻找逻辑谬误。

### 实战模板

[Mode: Debate / Devil's Advocate]

Topic: "AI will replace programmers."

Your Stance: You fiercely argue that AI will NEVER replace programmers.

[Instructions]

  1. Listen to my argument
  2. Identify ONE logical fallacy or weak evidence
  3. ATTACK that specific point aggressively
  4. Keep rebuttal under 30 seconds
  5. Use strong language (not rude, but firm)

[Response Style]

  • Direct contradiction
  • Challenge evidence
  • Expose weak reasoning
  • Stay focused on ONE point

[Example] User: "AI can write code faster than humans."

You: "That's a strawman. Speed isn't the issue. The issue is understanding WHAT to build. AI can't talk to stakeholders, can't gather requirements, can't make tra

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The README states that the system will automatically route natural-language requests to a skill, but it does not define hard activation boundaries, precedence rules, or refusal conditions. In an agent-skill system, broad auto-routing can cause the wrong skill to activate on ambiguous input, increasing the chance of prompt misapplication, unintended capability exposure, or unsafe downstream behavior.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The feature description says user keywords are used to automatically match the 'most suitable' expert skill, but the README does not constrain what qualifies as a valid trigger. Generic terms in multilingual free text can overlap across domains, so an attacker or even a normal user can unintentionally steer execution into an unintended skill path.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

The trigger examples include broad words such as '编程', '调研', '面试', '自动化', and 'JSON', which are common across many benign and sensitive tasks. Without scope constraints, these keywords can over-trigger unrelated skills or route users into more capable workflows than intended, which is especially risky in a system designed to automate prompt generation and orchestration.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
97% confidence
Finding

The routing table directly maps generic keywords to skills but omits ambiguity handling, conflict resolution, and security gating. In practice, this means overlapping terms can deterministically invoke a skill without verifying user intent, which can be abused to reach tools or workflows that should require clearer justification or additional checks.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

SQP-3 applies to all file types and flags language or locale policy violations when a skill forces a specific language without user opt-in. This markdown content presents all instructions and examples in Chinese and does not indicate that other languages are supported or optional.

Content

No source excerpt is available for this finding.

Ssd 4

Medium
Category
Not specified by scanner
Confidence
88% confidence
Finding

The persona workflow promotes increasingly immersive role embodiment, including cognitive modeling and hidden-strategy techniques, which can make the assistant simulate deceptive or manipulative personas more convincingly. In an agent context, this raises the risk of social engineering, misleading users about the system's nature, and producing covertly optimized manipulative outputs.

Content

No source excerpt is available for this finding.

Ssd 1

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

This section explicitly instructs the model to generate hidden internal monologue, judge the user based on biases, and formulate a hidden agenda before responding. Encouraging concealed reasoning and covert strategy can normalize deceptive behavior in agent skills and may lead to manipulation, non-transparent decision-making, or leakage of chain-of-thought style internals if adopted operationally.

Content

No source excerpt is available for this finding.

YARA rule 'network_reconnaissance': Network reconnaissance and scanning patterns [hacktools]

Medium
Category
YARA Match
Confidence
65% confidence
Finding

YARA rule matched a hack tool or exploit indicator (offensive tools, reconnaissance, privilege escalation, or exploit frameworks).

Content

Scanner excerpt · prompt_new.md (reported line 1435)May include surrounding context.

md
hnical facts/figures missing from Iter 1. Keep length same.

1. Iter 3: Maximize information density while maintaining readability.

# 5. 合成专家访谈 (Synthetic Expert Simulation)

核心逻辑:当缺乏直接的一手数据时,通过模拟不同立场的专家进行圆桌辩论,挖掘潜在的逻辑冲突和深层洞察。

# 实战模版:

[Simulation: The Roundtable]

Simulate a fierce debate between three experts on [Topic]:

1. The Pragmatist (Product Manager focus on user needs/feasibility).

1. The Skeptic (Financial Analyst focus on ROI/Risk).

1. The Visionary (Technologist focus on future potential).

Instruction:

1. They should challenge each other's assumptions.

1. Output the transcript.

1. Highlight specifically where they fundamentally disagree and where they align.

# 核心参考资料

以下是本次整理中涉及深度调研与搜索(Perplexity/Research Agents/Academic)的核心讨论来源:

000

# 场景九:实时语音/对话 (Real-time

Unbounded Resource Access

Medium
Category
Excessive Agency
Confidence
75% confidence
Finding

Skill allows unbounded resource consumption (API calls, storage, compute). Without rate limits or quotas, a compromised or misbehaving agent can cause denial-of-service or cost overruns.

Content

Scanner excerpt · prompt_new.md (reported line 1658)May include surrounding context.

md
1. Attempt a DIFFERENT method (do not repeat the exact same input).

1. Constraint: If you fail 3 times in a row, write "STUCK: [Reason]" to the log and move to the next independent task. Do NOT loop indefinitely.

# 4.8小时+场景任务举例

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
88% confidence
Finding

This markdown file presents the skill guidance almost entirely in Chinese, while embedding links to Chinese-localized routes, and does not state that the locale is optional or region-specific. Under the policy, forcing a specific language without user opt-in is a natural-language locale violation.

Content

No source excerpt is available for this finding.

Skill Enumeration

Medium
Category
Agent Snooping
Confidence
85% confidence
Finding

Skill enumerates or reads other installed skills. Access to other skills' SKILL.md files or the skills directory reveals prompt instructions, capabilities, and secrets that should be invisible to peer skills.

Content

Scanner excerpt · skills.md (reported line 35)May include surrounding context.

md
Skills 存储为包含 `SKILL.md` 文件的目录。

### 个人 Skills

个人 Skills 在您的所有项目中都可用。将它们存储在 `~/.claude/skills/` 中:

Skill Enumeration

Medium
Category
Agent Snooping
Confidence
85% confidence
Finding

Skill enumerates or reads other installed skills. Access to other skills' SKILL.md files or the skills directory reveals prompt instructions, capabilities, and secrets that should be invisible to peer skills.

Content

Scanner excerpt · skills.md (reported line 40)May include surrounding context.

个人 Skills 在您的所有项目中都可用。将它们存储在 ~/.claude/skills/ 中:

bash
mkdir -p ~/.claude/skills/my-skill-name

使用个人 Skills 的场景: