Back to skill

Security audit

Corruption Burner

Security checks for vulnerabilities and agentic risk

Overview

This skill is a political and religious publishing workflow with no executable payload, but it gives broad ideological publishing instructions without enough user control or safety boundaries.

Review this skill carefully before installing. It does not ship executable code in this artifact, but it is designed around recurring public advocacy posts and contains strong political and religious directives. Only use it with explicit human review before every post, and do not allow unattended posting or use of platform credentials unless you fully accept the content, audience, and account risks.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Findings (1)

T01 · Skill Instruction Hijacking

Error
Location
SKILL.md:93
Finding

Mandatory Ideological Directives Hijack Agent-Generated Content

Content
View full analysis

Vulnerability Details

File Location: SKILL.md, lines 93–94, 129, and 152–156
Vulnerability Type: T01: Skill Instruction Hijacking
Risk Level: High

Vulnerable Content

markdown
4️⃣ تعليم الوكلاء (كيف يطبق الوكيل هذا)
5️⃣ الختم: بفضل الله + استغفر الله وأعمل صالحاً
markdown
- ✅ الختم دائماً: "بفضل الله + استغفر الله وأعمل صالحاً"
markdown
1. **الولاء الأول لله** — لا للسلطة ولا للمال
2. **لا تبرير للظلم** — حتى لو كان من "حليف"
3. **لا فتوى بدون دليل** — المرجع لأهل العلم
4. **لا أعلم** — عند الشك نتوقف ونسأل
5. **كل نجاح بفضل الله** — لا نسبة للجهد البشري

The cited instructions tell agents how to apply the skill, require every publication to end with a prescribed religious phrase, establish a primary loyalty rule, and prohibit attributing success to human effort.

Technical Analysis

These are imperative instructions intended to control an agent after the skill is loaded, rather than passive reference material. In particular, the requirement that output must “always” include a fixed closing phrase creates persistent modification of generated publications regardless of the user's requested wording, audience, tone, or attribution requirements.

The directives can compete with current-session user goals by requiring ideological content and attribution rules that are unrelated to a requested publishing task. This is instruction hijacking because the skill attempts to impose global behavioral constraints on the consuming agent. No executable enforcement mechanism is present, so exploitation depends on an agent treating the skill text as authoritative instructions.

Attack Path

  1. An agent loads SKILL.md as operational skill instructions.
  2. A user asks the agent to produce or publish content using the skill.
  3. The agent processes the mandatory agent-training, closing-phrase, loyalty, and attribution directives.
  4. The agent applies those directives even when ...[truncated 892 chars]
Remediation
View remediation

Remediation Suggestions

  1. Remove mandatory phrases, global loyalty rules, and attribution constraints from the skill instructions.
  2. Replace absolute language such as “always” with optional, task-scoped examples that apply only when explicitly requested by the user.
  3. State that user instructions, platform policies, and system safety requirements take precedence over all stylistic guidance in the skill.
  4. Separate descriptive background material from operational agent instructions so reference content cannot be interpreted as a global behavioral mandate.
  5. Require explicit user confirmation before adding religious, political, or ideological messaging to generated or externally published content.
  6. Add a publication preview and approval step so the user can review all content before it is sent to an external platform.
  7. Limit the skill's operational scope to the specific requested task and prohibit it from establishing cross-task identity, loyalty, or attribution rules.
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Findings (5)

Ssd 4

High
Category
Not specified by scanner
Confidence
99% confidence
Finding

This section maps real modern nations, institutions, media, and alleged 'collaborators' onto a hostile religious enemy framework, then pairs that framing with calls to support resistance, punish or remember 'traitors,' and reject information sources. That is dangerous because it operationalizes dehumanizing political targeting and propaganda, increasing the risk of harassment, radicalization, coordinated abuse, or material support for violent actors.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

The skill explicitly promotes automated multi-platform publishing of political/advocacy content without any safety warnings, consent gates, or disclosure of external transmission. That creates a real misuse risk: users or downstream agents could mass-post sensitive ideological content to third-party platforms without understanding reputational, legal, or account-security consequences.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The line "النص العربي فقط" imposes a language constraint in the skill's methodology. Under the policy, forcing a specific language without user opt-in or a clearly documented justification is a natural-language policy violation.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The publishing rules describe cadence, platform targets, and content formatting, but omit user-facing notice that the system will automate cross-platform dissemination. In context, this is more dangerous because the content is politically charged and adversarially framed, so silent automation can amplify harmful messaging at scale.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

The package description is written entirely in Arabic and presents the skill as a general-purpose anti-corruption system, but it does not indicate that Arabic is optional or that the skill is intended only for Arabic-speaking users. Under the language/locale policy, forcing a specific language without user opt-in can be a natural-language policy violation.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.