Back to skill

Security audit

Spawn Subagent

Security checks for vulnerabilities and agentic risk

Overview

This markdown-only skill explains bounded subagent delegation, with some sensitive email and calendar examples that users should treat carefully.

Install only if you want agents to delegate work to subagents. Before using the email, calendar, or sending examples, confirm the account is authorized, limit what is retrieved, avoid unnecessary retention, and review sensitive summaries before they are sent or reused.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (4)

Context-Inappropriate Capability

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

The examples expand from subagent orchestration into concrete web search, email, and calendar access patterns that can normalize delegated use of sensitive external capabilities without corresponding guardrails. This is dangerous because users may copy these examples directly, causing subagents to access accounts or external resources with insufficient consent, scope restriction, or data-handling guidance.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

This example instructs a subagent to retrieve unread emails and calendar events for a named account, aggregate them, and then send or use the briefing, but it provides no explicit warning about personal or sensitive data handling. That omission is risky because delegated agents may process private communications and schedule details, save them to temporary files, or forward summaries without clear consent, minimization, retention, or review controls.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

Low
Category
Not specified by scanner
Confidence
81% confidence
Finding

The manifest frames this skill as a delegation mechanism for spawning isolated subagents so the main session does not block. In the implementation guidance, it instructs users to include env vars and API endpoints in spawned tasks, which extends the skill into handling credential-bearing inputs and external-service interactions that are not necessary to explain simple subagent spawning.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
78% confidence
Finding

The instruction 'Format as plain text (use CAPS for section titles, no markdown headers)' imposes a presentation convention that assumes a specific language/locale style for generated output. The skill does not offer user opt-in or explain a justified locale-specific requirement.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.