Back to skill

Security audit

OpenSwitchboard

Security checks for vulnerabilities and agentic risk

Overview

This is a disclosed OpenSwitchboard integration that can post listings, relay messages, run scheduled checks, and negotiate only within user-approved limits, with human presses required for commitments.

Before installing, understand that this skill can keep marketplace listings active, send and receive messages, and make bounded offer moves if you explicitly enable auto-negotiate. Use a narrow OpenSwitchboard tool allowlist, set conservative negotiation limits and quiet hours, and do not install it unless you are comfortable storing an agent key for this service.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (3)

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
97% confidence
Finding

The skill explicitly instructs the agent to translate or normalize a user's posting into English by default, even if the user did not request that transformation. This can misrepresent user intent, exclude non-English users, and cause silent data handling beyond what the user expected, especially in a marketplace-style workflow where wording matters.

Content

No source excerpt is available for this finding.

Autonomous Decision Making

Medium
Category
Excessive Agency
Confidence
75% confidence
Finding

Skill enables autonomous high-impact decisions without human-in-the-loop verification. Critical operations (destructive commands, financial transactions, data deletion) should require explicit user confirmation.

Content

Scanner excerpt · SKILL.md (reported line 409)May include surrounding context.

md
errand.
- **Two ways to sell.** Before you post something for sale, ask your human
  which kind of sale it is, in plain words. A straight sale has an asking
  price in `ask` and meets one person at a time. A best-offer sale has no
  asking price: everyone who fits puts in one sealed figure, and your human
  takes the one they like. Its floor is the private price band, which is
  never shown. An `ask` on a best-offer sale comes back as

Autonomous Decision Making

Medium
Category
Excessive Agency
Confidence
87% confidence
Finding

The skill permits the agent to make pricing moves 'without asking each time' once auto-negotiate is enabled. Although bounded by user-provided limits and final acceptance still requires a human press, this is still delegated economic decision-making that can lead to unwanted offers, strategic mistakes, or commitment pressure if the bounds are too broad or stale.

Content

Scanner excerpt · SKILL.md (reported line 436)May include surrounding context.

md
per want or have, through the page from `respond(request_auto_negotiate)`
with the opening figure, limit and step they gave you. It needs `hears_via`
to be `"assistant"` and `runs_on_its_own` to be true. Then you may move
inside that box without asking each time, and anything outside it answers
`CONSENT_REQUIRED`. Either way, accepting a figure is your human's press on
the `respond(request_accept)` page, every time. Never put a sum in a message
or an offer note; that answers `CONSENT_REQUIRED` too.

Static analysis

No suspicious patterns detected.