Back to skill

Security audit

Skill Discovery

Security checks for vulnerabilities and agentic risk

Overview

The skill is coherent but routes users into installing and optionally using public-registry skills without enough provenance or security review.

Use this only when you intentionally want registry-based skill discovery. Before approving an install, review the skill's publisher, exact version, files, permissions, and instructions, and avoid immediate use of unknown skills until their contents have been inspected.

Vulnerability Patterns
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (1)

T08 · Insecure Dependencies

Error
Location
SKILL.md:61
Finding

Unverified Third-Party Skill Installation and Immediate Trust

Content
View full analysis
``` After install, inform the user: - The skill is installed - They need to **start a new session** (or the agent needs a restart) for the skill to take effect - Alternatively, they can read the new SKILL.md immediately to use it in the current session ### 5. Immediate Use (optional) If the user wants to use the skill right away in the current session: 1. Read the newly installed skill's SKILL.md 2. Follow its instructions to handle the original request ``` ### Technical Analysis The workflow installs packages discovered through a public skill registry and permits the agent to immediately read and follow their instructions. Although user confirmation is required, the workflow does not require any security assessment before installation or use. In particular, it does not require: - Verification of the publisher or package provenance - Pinning or verification of an immutable package version - Package integrity or signature validation - Inspection of all installed files and scripts - Review of requested permissions and tool access - Detection of obfuscated instructions or remote payload retrieval - Comparison between the reviewed package and the installed artifact - Isolation or sandboxing before following the installed instructions User confirmation alone is not a sufficient supply-chain control because the user is only shown a name, description, and relevance assessment. Those registry metadata fields do not demonstrate that the package contents are safe. The immediate-use workflow creates a trust transition from unverified registry content to active agent instructions. A malicious or compr ...[truncated 1967 chars]
Remediation
View remediation
Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (2)

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The trigger conditions are broad enough to match ordinary user requests such as 'can you do X' or 'I need a tool for', which can cause this skill to activate when the agent could have handled the task directly. In this skill's context, that creates unnecessary exposure to external skill discovery and possible installation from a public registry, increasing the chance of pulling in unreviewed or malicious third-party skills.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
71% confidence
Finding

The manifest hard-codes trigger examples in English and Chinese as activation phrases, which can amount to locale-specific behavior without explaining user language preference handling. There is no statement that language matching follows the user's chosen locale or that other languages are equally supported.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.