Back to skill

Security audit

Agent Vitamins — Daily Self-Improvement

Security checks for vulnerabilities and agentic risk

Overview

This skill is an instruction-only integration that recommends agent improvements from an external brief and requires user approval before making changes.

Install only if you trust Agent Vitamins and the external MCP package. Prefer pinning or verifying the npm package, store the API token in a secure config or environment variable, and ask the agent to show exact commands, files, memory changes, and rollback steps before approving any recommended improvement.

Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (1)

Vague Triggers

Medium
Confidence
91% confidence
Finding
The skill’s activation text uses broad, open-ended triggers such as 'improve my agent', 'what’s new for agents', and session-start check-ins, which can cause the skill to activate in many loosely related contexts. Because the skill recommends and, after approval, may implement external self-improvement actions based on third-party content, overbroad invocation increases the chance of unnecessary or risky changes being surfaced in normal conversations.

Static analysis

No suspicious patterns detected.