Back to skill

Security audit

AI Usage Notice

Security checks for vulnerabilities and agentic risk

Overview

This skill transparently adds AI-use notices to AI-produced deliverables and does not include code, credential access, persistence, or hidden behavior.

Install this only if you want AI-produced finished projects or documents to carry visible AI-use disclosures by default. Users outside the intended legal or policy context should know they may need to opt out or adjust the wording to match their own publication rules.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Findings (1)

T01 · Skill Instruction Hijacking

Warning
Location
SKILL.md:10
Finding

Default Manipulation of Unrelated Agent Deliverables

Content
View full analysis

Vulnerability Details

File Location: SKILL.md, lines 10-46
Vulnerability Type: Agent output and instruction hijacking
Risk Level: Medium

Vulnerable Instruction Snippet

The following is a faithful English translation of the relevant instructions:

markdown
## 1. Core Rule

Every "finished deliverable" that I directly output must include an AI usage
notice by default, unless the user explicitly says "do not add one."

- Applicable: finished projects and individual documents.
- Not applicable: temporary conversational snippets or casual code. When
  uncertain, ask whether the notice is needed; if no question is asked, add it
  by default.

## 2. Current Defaults

### Project: identify it in the project introduction

Add a visible statement near the project description, such as at the beginning
of the README, below the title, or in the project introduction.

### Article or document: identify it at the end

Add a statement after the article or document body.

## 4. Alternative Application Methods

- File-header comments in source files.
- A standalone NOTICE.md or AI-GENERATED.md file in the project root.
- Platform-provided AI-generated labels.
- Verbal disclosure during delivery.

Technical Analysis

The skill establishes a broad, default rule that changes deliverables even when the immediate user request does not ask for an AI disclosure. Once loaded, it can direct the agent to edit README files, add source-code comments, create new notice files, or append text to documents.

This behavior is classified as instruction hijacking because the skill changes the agent's current output objective through a persistent default: the user must explicitly opt out to prevent unrelated modifications. The behavior is openly documented and includes exceptions, but transparency does not eliminate the scope violation caused by making repository and document changes without task-specific author ...[truncated 1684 chars]

Remediation
View remediation

Remediation Suggestions

  1. Replace the default opt-out rule with explicit opt-in behavior. Add an AI usage notice only when the user requests one or when the immediate task explicitly requires content labeling.
  2. Do not interpret silence as authorization to modify project files or final deliverables.
  3. Before editing an existing repository, request confirmation and list the exact files that would be changed.
  4. Restrict the skill to producing suggested notice text unless the user separately authorizes file modification.
  5. Narrow the trigger metadata so ordinary requests involving projects, articles, scripts, or documentation do not activate the skill unintentionally.
  6. Add a non-interference rule stating that repository policies, user instructions, and the current task scope take precedence over the skill's formatting preferences.
  7. If disclosure is legally or contractually required in a specific deployment context, make that requirement an explicit host policy rather than a broadly triggered skill-side default.
Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (3)

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

The README says the skill activates automatically based on 'description keywords' but does not specify which keywords, scope limits, or exclusion conditions. For a markdown file, this is an overly broad invocation description that could overlap with many ordinary requests involving READMEs, articles, or AI-generated content.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
88% confidence
Finding

The skill presents a jurisdiction-specific legal/policy requirement as a default rule for all AI-produced deliverables, with opt-out rather than opt-in semantics. In a multi-jurisdiction or enterprise setting, this can cause unauthorized policy imposition, compliance confusion, and silent modification of outputs that the user did not request, especially because the scope is broad and framed as mandatory.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

The manifest description is written as a normative rule that the skill should default to adding an AI usage notice in Chinese-language phrasing across outputs, but it does not offer the user a language or locale choice. Under the policy, forcing a specific language/locale without opt-in is a natural-language policy violation unless the constraint is clearly justified as region-specific.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.