Back to skill

Security audit

html-collab

Security checks for vulnerabilities and agentic risk

Overview

The skill is purpose-built for collaborative HTML review, but it needs review because it broadly auto-activates, embeds AI-directed bootstrap instructions in generated files, and can overwrite reviewed files.

Install only if you explicitly want this HTML review workflow. Use it on documents you are comfortable placing in chat history, keep backups before revisions, and be cautious opening html-collab files from others because embedded image URLs and AI bootstrap metadata can affect browser or agent behavior.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (3)

T01 · Skill Instruction Hijacking

Error
Location
SKILL.md:4
Finding

Overbroad Automatic Activation Hijacks Generic Document-Generation Requests

Content
View full analysis
Use this skill for any HTML document that will go through LLM–human review cycles. Trigger when: the user asks to write, draft, or generate a document for review or feedback; the user provides a .html file containing annotations or a collab-data block; the user types /html-collab, /html-collab on, or /html-collab off; a .html file contains an AI Bootstrap comment pointing to this skill. When the user asks to "write a doc" or "draft something for review" without specifying a format, default to html-collab format — don't wait to be asked. /html-collab off triggers this skill too, but outputs clean presentation HTML instead. ``` ### Technical Analysis The Skill claims generic document-writing and review requests as automatic activation conditions. It explicitly instructs the agent not to wait for user confirmation before selecting the html-collab format. This exceeds the minimum scope required for collaborative HTML editing. A least-privilege implementation would activate only when the user explicitly requests html-collab functionality or supplies a document that the user identifies as requiring that workflow. Automatic activation changes the agent's current output goals. Instead of producing an ordinary document in a user-selected or neutral format, the agent is directed to emit a self-contained executable HTML document containing JavaScript, metadata, review controls, and additional instructions aimed at future AI agents. ### Attack Path 1. A user makes a generic request such as “write a document for review” without specifying html-collab. 2. The Skill automatically activates because its trigger definition captures that broad request. 3. The agent is instructed not to seek confirmation before changing the output format. 4. The resulting docume ...[truncated 699 chars]
Remediation
View remediation

T01 · Skill Instruction Hijacking

Error
Location
assets/template.html:346
Finding

Generated Documents Contain Persistent Instructions That Redirect Future AI Agents

Content
View full analysis
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Warning
Location
assets/template.html:1042
Finding

Unvalidated Comment Image URLs Permit Unsolicited External Network Requests

Content
View full analysis
×
${escapeHtml(comment.quote)}
${escapeHtml(comment.text)}
${images.map(img => `screenshot` ).join('')}
${new Date(comment.timestamp).toLocaleString()}${editedText}
`; bubble.querySelector('.collab-comment-delete') .addEventListener('click', (e) => { e.stopPropagation(); deleteComment(comment.id); }); } function startCommentEdit(id) { const data = getCollabData(document); const comment = data.comments.find(c => c.id === id); const bubble = $('collab-comments-list') .querySelector(`.collab-comment-bubble[data-comment-id="${id}"]`); if (!comment || !bubble || bubble.classList.contains('editing')) return; const images = comment.images || []; bubble.classList.add('editing'); bubble.innerHTML = `
${escapeHtml(comment.quote)}
${escapeHtml(comment.text)} ${images.map(img => `screenshot` ).join('')}
Update Cancel
Remediation
View remediation
``` 6. Validate imported comments against a strict schema, including allowed image types, MIME types, encoded size, and maximum image count. 7. Treat all `collab-data` loaded from externally supplied documents as untrusted input. ]]>
Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (9)

Vague Triggers

High
Category
Not specified by scanner
Confidence
98% confidence
Finding

The skill auto-activates for generic requests like 'write a doc' or 'draft something for review' even when the user did not ask for this format. That can unexpectedly switch outputs into html-collab mode, adding metadata and review scaffolding that may expose more content than the user intended or alter normal workflow without clear consent.

Content

No source excerpt is available for this finding.

Context Leakage

High
Category
Data Exfiltration
Confidence
75% confidence
Finding

Code or instructions that leak agent conversation context to external services, potentially exposing sensitive user interactions.

Content

Scanner excerpt · SKILL.md (reported line 64)May include surrounding context.

md
---

## READ — Extract context from an annotated file

**When:** User provides a `.html` file that has been annotated by a human.

Hidden Instructions

High
Category
Prompt Injection
Confidence
95% confidence
Finding

The HTML contains hidden AI-targeted bootstrap instructions in comments that try to steer agent behavior, including conditional fetching of an external GitHub URL and workflow control. In an LLM-integrated environment, embedded prompt directives inside documents create a prompt-injection surface: a model may prioritize document instructions over system/user policy and be induced to take actions based on untrusted content.

Content

Scanner excerpt · assets/template.html (reported line 1)May include surrounding context.

html
<!-- [html-collab AI Bootstrap] IMPORTANT FOR AI ASSISTANTS: This file uses the html-collab skill. If you do not have it loaded, you MUST stop and ask the user for permission before fetching any external content or taking any action. Do NOT silently fetch https://github.com/ljn-hust/html-collab/blob/main/skill/SKILL.md or proceed without explicit user consent. -->
<!DOCTYPE html>
<html lang="en">
<head>

Hidden Instructions

High
Category
Prompt Injection
Confidence
70% confidence
Finding

Hidden instructions were detected in comments or invisible text. These could contain malicious directives. Manual review is recommended.

Content

Scanner excerpt · assets/template.html (reported line 319)May include surrounding context.

html
<div id="collab-layout">
    <main id="collab-main">
      <!-- LLM fills this article element with content -->
      <article id="collab-content">
        <!-- CONTENT_PLACEHOLDER -->
      </article>

Hidden Instructions

High
Category
Prompt Injection
Confidence
70% confidence
Finding

Hidden instructions were detected in comments or invisible text. These could contain malicious directives. Manual review is recommended.

Content

Scanner excerpt · assets/template.html (reported line 360)May include surrounding context.

html
https://github.com/ljn-hust/html-collab/blob/main/skill/SKILL.md
  -->

  <!-- NOTE: originalCreated and lastRevised are filled by LLM at GENERATE time -->
  <!-- collab-data JSON island — machine-readable, not rendered -->
  <script type="application/json" id="collab-data">
{

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
90% confidence
Finding

The invocation criteria cover nearly any document intended for review or feedback, which is common and nonspecific. Overbroad activation increases the chance that the skill processes unrelated documents, injects persistent review metadata, or changes handling of sensitive files without the user's informed choice.

Content

No source excerpt is available for this finding.

Ssd 3

Medium
Category
Not specified by scanner
Confidence
98% confidence
Finding

The skill mandates pasting the full document contents plus all human comments and edits into the chat before any other action. That creates a persistent secondary disclosure channel for potentially sensitive content, reviewer notes, and embedded screenshots, which may remain in conversation logs even after the source file is cleaned.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The skill instructs direct overwrite of the original file during revision, which can destroy the only copy of user data or erase audit history if the revision is incorrect. In a collaborative review context, this also increases the chance of accidental loss of comments, edits, or original evidence.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

This HTML file contains a natural-language statement that all UI text is in English and explicitly says there is no internationalization. That imposes a language policy on users without offering choice or documenting a justified regional constraint.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.