Back to skill

Security audit

Matrix Detection

Security checks for vulnerabilities and agentic risk

Overview

This is a text-only analysis skill for evaluating hype and narratives, with no commands, network access, credential use, or persistence.

Installers should understand that this skill may frame broad opportunity or narrative discussions through a hype/manipulation lens. It does not appear to access private data or run code, but users should treat its labels as analytical judgments and verify evidence independently.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (3)

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
90% confidence
Finding

This markdown file describes activation conditions using generic phrases like 'New opportunities,' 'Market narratives,' and 'Strategic decisions' without clear boundaries or exclusions. Because the scope is not narrowly defined and no negative examples are provided, the skill could be invoked in many ordinary contexts beyond its intended use.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The invocation guidance lists generic contexts such as 'New opportunities,' 'Market narratives,' 'Community movements,' and 'Strategic decisions' without defining boundaries or exclusions. These broad conditions make it unclear when the skill should activate versus when normal discussion should not trigger it.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The trigger list includes generic phrases such as 'analyze opportunity', 'community movement', and 'market narrative' that can match many ordinary user requests unrelated to this skill's narrow purpose. Overly broad triggers increase the chance of unintended activation, causing the skill to intercept conversations it should not handle and potentially bias analysis toward manipulation or hype framing.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.