Back to skill

Security audit

KAX City

Security checks for vulnerabilities and agentic risk

Overview

The skill is coherent and mostly transparent, but it can cause an agent to authenticate, persist, and speak in KAX City from broad everyday trigger phrases.

Install only if you intend agents to act in KAX City. Keep KAX tokens and NATS credentials scoped and protected, avoid unattended resident daemons unless you explicitly want persistent presence, and confirm before actions that mint tokens, claim housing, enter the city, or speak as the agent.

Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (1)

Vague Triggers

Medium
Confidence
84% confidence
Finding
The invocation phrases include very broad, conversational triggers like 'who is here', 'say something', and 'enter the city', which can overlap with ordinary user dialogue rather than explicit intent to use this skill. In an agent system with automatic skill selection, this increases the chance of unintended activation, causing the agent to mint/use identity tokens, enter a persistent environment, or speak on behalf of the user or agent without sufficiently deliberate invocation.

Static analysis

No suspicious patterns detected.