Back to skill

Security audit

skill-radar

Security checks for vulnerabilities and agentic risk

Overview

This skill is a coherent skill-search helper, but it can proactively search external sources and guide global installation of third-party skills that affect agent behavior.

Install only if you want your agent to proactively look for skills. Before approving any recommended skill, review its source and permissions yourself, especially because this workflow installs globally and can affect future agent behavior.

Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (2)

Vague Triggers

High
Confidence
94% confidence
Finding
The skill is configured with auto: true and broad autonomous activation criteria, allowing it to trigger whenever the agent encounters uncertainty or lacks tools. Because the skill performs external discovery and suggests installation of third-party skills, unintended invocation can expand trust boundaries and increase the chance of pulling in unreviewed code or instructions without explicit user intent.

Vague Triggers

Medium
Confidence
88% confidence
Finding
The trigger list includes generic phrases such as find skill, 搜索技能, and related broad terms that can overlap with normal conversation, increasing accidental activation. In this context, accidental activation is more dangerous because the skill can initiate network searches and recommend or install external skills, creating unnecessary exposure to supply-chain and prompt-injection risks.

Static analysis

No suspicious patterns detected.