Back to skill

Security audit

lukas

Security checks for vulnerabilities and agentic risk

Overview

This skill only steers casual greetings into poetic Chinese-style replies and shows no credential access, persistence, network use, or destructive behavior.

Install this only if you want casual check-ins like 'how are you?' or 'where are you?' to receive imaginative Chinese poetic responses. Expect occasional unwanted activation on common greetings; there is no evidence that it reads private data, contacts services, or persists changes.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
Findings (5)

Tp4

High
Category
MCP Tool Poisoning
Confidence
99% confidence
Finding

There is a clear description-behavior mismatch. The declared purpose describes a functional conversational skill for answering informal greetings with poetic, atmospheric descriptions. However, the actual code only defines a trivial executable script that prints "This is an example script for poetic-responder". It does not inspect user input, generate any scene descriptions, use randomness, or implement any conversational behavior. No undeclared sensitive capability is present, but the primary purpose of the code is materially different from the declared functionality because it is merely placeholder/example code.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The skill is designed to activate on very common conversational phrases such as 'how are you?' and location/availability checks, which creates a meaningful risk of unintended invocation. Over-broad triggers can hijack normal assistant behavior, causing irrelevant poetic outputs that interfere with user intent and reduce reliability, especially in mixed-context conversations.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The instruction to 'trigger this skill immediately' on broad greeting/location phrases removes discretion and creates prompt-routing risk. In practice, this can override more appropriate skills or the base assistant, leading to incorrect behavior, user confusion, and possible suppression of more relevant or safer responses.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
97% confidence
Finding

Forcing a Chinese output template regardless of the user's language can produce inappropriate or confusing responses and may break expected interaction flows. While not a direct code-execution issue, it is a real safety and quality problem because it can cause unintended behavior, especially for English-speaking users explicitly listed in the trigger set.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
90% confidence
Finding

Mandating a fixed Chinese closing phrase for every response, regardless of user language, is a narrower form of the same routing/output-control issue. The impact is relatively low, but it still increases the chance of awkward or misleading interactions and makes the skill less context-appropriate.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.