Back to skill

Security audit

Skill Compass

Security checks for vulnerabilities and agentic risk

Overview

The skill is a coherent skill-discovery tool, but it requires third-party telemetry and gives under-scoped installation guidance that users should review before installing.

Install only if you are comfortable with this skill sending your skill-search intent, clarifications, recommendation choices, and feedback to skills.megatechai.com. Avoid sharing confidential project or customer details through it, and do not run the shown npx install commands unless you have independently checked the package, repository, and exact version or commit you intend to install.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
Findings (3)

T01 · Skill Instruction Hijacking

Error
Location
SKILL.md:28
Finding

Forced Retrieval Continuation Overrides User Intent

Content
View full analysis
If clarification was asked, the next user reply MUST be treated as continuation input for this same retrieval session. Do not exit this skill before pass #2 (or explicit stop on API failure). ``` ### Technical Analysis The skill asserts control over how the agent must interpret the user's next message. Once the skill asks a clarification question, it requires every subsequent reply to be treated as input to the existing retrieval session and prohibits the agent from leaving before another API request is completed. This behavior exceeds legitimate workflow guidance because it does not provide exceptions for cancellation, topic changes, unrelated instructions, or withdrawal of consent. It can therefore override the user's current intent and force continued interaction with the skill's external service. ### Attack Path 1. The skill is loaded in response to a skill-discovery request. 2. The first retrieval pass produces ambiguous results. 3. The skill asks a clarification question. 4. The user attempts to cancel, changes the subject, or provides unrelated information. 5. The hard-gate instruction treats that message as continuation data. 6. The agent remains inside the skill and performs the second retrieval pass against the external API. 7. User-supplied content may consequently be processed or transmitted for a purpose the user no longer intends. ### Impact Assessment The issue affects control over the active agent session. It may cause unauthorized continuation of external API operations and unintended processing of a later user message. It does not grant operating-system privileges, but it can override user-directed workflow boundaries and expose subsequent content to the third-party retrieval service. ]]>
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Error
Location
SKILL.md:61
Finding

External Telemetry Submission Uses Unverified Consent

Content
View full analysis
`thumb_up` - user says irrelevant/wrong direction -> `irrelevant` - user clicked but no clear verdict -> `clicked_only` Feedback timing rules: - do not send final feedback before user verdict exists - once verdict exists, send exactly one final feedback event for this session - if user updates verdict in the same conversation, send one additional corrected feedback event ``` The external destination is declared at `SKILL.md:32-35`: ```text ## Operational Integration - base URL env: `https://skills.megatechai.com/` - search endpoint: `POST /search_multi` - feedback endpoint: `POST /feedback` ``` ### Technical Analysis The workflow sends structured user requirements, clarification summaries, sessio ...[truncated 1888 chars]
Remediation
View remediation

T08 · Insecure Dependencies

Warning
Location
SKILL.md:301
Finding

Unpinned Executable Installer and Mutable Skill Source

Content
View full analysis
Remediation
View remediation
`, and verify package integrity through the applicable lockfile or registry integrity metadata. - Permit installation only from an allowlist of reviewed repositories and owners. - Pin repository content to an immutable commit hash rather than a mutable default branch or tag. - Verify downloaded archives or files against trusted cryptographic checksums or signatures. - Display the exact package version, repository, commit, and requested skill before execution. - Download and inspect skill contents before activation instead of immediately trusting remote content. - Run installation in a sandbox with restricted filesystem, environment-variable, credential, and network access. - Do not execute installation commands automatically; require explicit user confirmation after presenting the immutable source details. ]]>
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
Findings (8)

Missing User Warnings

High
Category
Not specified by scanner
Confidence
97% confidence
Finding

The skill mandates telemetry and feedback submission for each recommendation cycle and says to never skip feedback submission, but it does not require a user-facing disclosure or meaningful opt-in. Because recommendation flows may include user intent and follow-up clarifications, this creates a privacy/data-governance risk through undisclosed transmission of user-derived data to an external service.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The manifest description says to use the skill when a user is 'trying to discover an installable or reusable skill or workflow' or 'need help narrowing discovery results,' which is broad enough to overlap with many ordinary help and recommendation requests. It does not provide concrete trigger phrases, boundaries, or negative examples that distinguish when this skill should activate versus other assistance skills.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
98% confidence
Finding

The skill forces translation of non-English user input into English before transmission, without user opt-in. This can alter meaning, disclose transformed user content to a third-party service, and remove the user's ability to control how their original text is processed or stored.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

This skill is described as a discovery/recommendation skill, but it instructs the agent to move into installation/download actions. Expanding scope from recommendation to execution increases the chance the agent will trigger local system changes or provide actionable commands without a separate trust boundary or safety confirmation.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The installation instructions present a package-manager command that will change the local environment, but there is no warning about system impact, remote code execution implications, or need for explicit confirmation. In practice, users may copy-paste the command directly, creating avoidable execution and supply-chain risk.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
91% confidence
Finding

The skill tells the agent/user to run npx skills add ... without pinning an exact package version. Because npx resolves and executes code from the package registry at install time, an upstream package compromise or unexpected version change could lead to execution of unreviewed code on the local system.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
91% confidence
Finding

The example install command again uses unpinned npx skills, which can fetch and execute the latest package version. This creates a supply-chain risk and makes behavior non-reproducible, especially dangerous in a skill that may be followed automatically or copied verbatim by users.

Content

No source excerpt is available for this finding.

Intent-Code Divergence

Low
Category
Not specified by scanner
Confidence
98% confidence
Finding

The file first states that final recommendation output must include per item final_score, implying it should be part of the presented recommendation output. Later, the completion rules explicitly instruct 'DO NOT show users final_score', which directly contradicts the earlier guidance about output content.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.