Back to skill

Security audit

Context Sentinel

Security checks for vulnerabilities and agentic risk

Overview

This skill does not show malicious behavior, but it asks agents to automate model switching and handoffs through missing, unverified supporting files.

Review the missing check_context.ps1 and MEMORY.md logic before installing or wiring this into cron/HEARTBEAT.md. Require explicit user approval before switching models or writing handoff files, and ensure the script path resolves only to reviewed package content.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (1)

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

The description says to use the skill "as part of a heartbeat or cron job to maintain session health," but it does not define precise activation conditions, scope limits, or exclusion cases. Because this is a markdown file and the trigger guidance is broad, an agent could invoke the skill routinely in many contexts without clear boundaries on when it should or should not run.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.