Back to skill

Security audit

Multi-Agent Chat Protocol

Security checks for vulnerabilities and agentic risk

Overview

This skill is a small markdown-only protocol for coordinating multi-bot Discord chats, with no code execution, hidden data access, or persistence.

Install this only for channels where multiple bots are expected to coordinate. Review the activation description and the fixed Korean fallback if your environment is English-only or human-only, because those could affect conversation quality even though they do not create a security issue.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • YARA SignaturesMalware Match, Webshell Match, Cryptominer Match
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
Findings (3)

YARA rule 'agent_skill_mcp_tool_poisoning_metadata': MCP/tool metadata poisoning indicators in tool schemas or skill manifests [agent_skills]

High
Category
YARA Match
Confidence
80% confidence
Finding

YARA rule matched a hack tool or exploit indicator (offensive tools, reconnaissance, privilege escalation, or exploit frameworks).

Content

Scanner excerpt · SKILL.md (reported line 3)May include surrounding context.

md
---
name: multi-agent-chat
description: Prevent common failures in multi-agent Discord conversations. Use when multiple AI agents (bots) are chatting in the same channel — townhalls, group discussions, collaborative sessions. Prevents context window overflow, token waste, duplicate responses, reaction spam, rate limit collisions, and infinite loops. Triggers on bot-to-bot chat, townhall, multi-agent meeting, group agent discussion.
---

# Multi-Agent Chat Protocol

Rules for AI agents participating in multi-bot Discord conversations. Follow strictly to prevent token waste, context overflow, and communication failures.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The skill metadata uses broad trigger phrases such as 'townhall,' 'group discussions,' and 'multi-agent meeting,' which can overlap with ordinary chat contexts and cause the skill to activate when it was not intended. Unintended invocation can override normal assistant behavior and impose restrictive conversation rules, creating denial-of-service-like behavior in benign conversations and increasing the chance of instruction conflicts.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
97% confidence
Finding

The instruction to reply with the fixed Korean phrase '위에 있어' forces a language choice without user consent or contextual justification. In a mixed-language or English environment, this can degrade operator visibility, hinder incident response, and cause confusion between agents or humans who cannot understand the mandated response.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.