Back to skill

Security audit

Org Role Handoff

Security checks for vulnerabilities and agentic risk

Overview

This skill is a role-perspective response guide with no hidden execution, data access, network use, or persistence found.

Installers should understand that this skill changes response framing when users ask for company roles. It should be used where role-based perspective is desired, and users should clarify ambiguous shorthand like PM, BA, QA, or admin to avoid an unintended role lens.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
Findings (8)

Tp4

High
Category
MCP Tool Poisoning
Confidence
99% confidence
Finding

There is a clear mismatch between the declared purpose and the actual code. The description claims functionality related to assuming organizational roles and responding from those perspectives, but the code does not implement any such behavior. It does not process user input, model roles, validate role scope, or generate responses. Instead, it simply prints a static 'not implemented' message and exits. This is a materially different primary purpose from the declared description.

Content

No source excerpt is available for this finding.

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 31)May include surrounding context.

md
12. Read `references/multi-role-response-rules.md` when the user asks for more than one role in the same request.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

The activation description is broad enough to match many ordinary user requests such as 'act as' or 'speak from the perspective of,' which can cause unintended invocation or over-application of the role-handoff behavior. In a multi-skill agent, this increases the chance of prompt-routing mistakes, role confusion, and responses framed with inappropriate authority or scope, which can mislead users or bypass more specific safety-oriented skills.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The casual trigger examples use broad phrases like 'answer as Business Analyst', 'handle this as Web Developer', and 'respond as Graphic Designer' that can match ordinary user language without enough scoping. In a role-handoff skill, overly permissive activation increases the chance of unintended invocation, causing the agent to adopt a role-specific framing that may bypass normal expectations, especially for authoritative roles like IT Director or Executive Director.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
90% confidence
Finding

The abbreviation "pm" is ambiguous and widely used for multiple meanings such as project manager, product manager, private message, or time notation. In this skill, auto-mapping it to Product & Project Manager risks misclassification and could make the system respond from an unintended business decision-making role without sufficient user intent.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
90% confidence
Finding

The abbreviation "ba" is too short and overloaded, with possible meanings unrelated to Business Analyst. Because this skill changes behavior based on detected role, a mistaken mapping can alter the perspective, responsibilities, and recommendations the agent provides, creating reliability and authorization-boundary issues.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The synonym "admin" is highly generic and commonly appears in many unrelated contexts, so mapping it directly to General Administration can cause incorrect role activation. In a role-handoff skill, that can lead to the agent adopting unintended authority, workflow assumptions, or response style based on a casual word rather than a clear user request.

Content

No source excerpt is available for this finding.

Vague Triggers

Low
Category
Not specified by scanner
Confidence
76% confidence
Finding

The abbreviation "qa" is somewhat ambiguous, though less dangerous than terms like "admin" because it more commonly maps to Quality Assurance in technical contexts. Still, without scope constraints, it can trigger the wrong role when users use the abbreviation in a different sense, causing incorrect role-based responses.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.