Back to skill

Security audit

Startup Mentor

Security checks for vulnerabilities and agentic risk

Overview

This startup-advice skill is a plain Markdown guidance skill with purpose-aligned use of web research and no executable code, persistence, or hidden privileges.

Before installing, understand that this skill may use web searches for startup research. Do not include confidential strategy, customer data, financials, or unreleased product details unless you are comfortable with them being used to form external search queries.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (3)

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The invocation phrases are overly broad and can cause the skill to trigger on generic business questions that may not actually call for this specialized workflow. This increases the chance of unintended activation, causing irrelevant guidance, unexpected tool use, or interception of user requests that should be handled by a different, narrower skill.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The skill explicitly directs the agent to use web_fetch and search tools to gather external data, but it does not disclose that external retrieval may occur or obtain user confirmation. This can lead to privacy and data-handling issues if user-provided business details are used to formulate external queries, and it may surprise users who expected a local-only response.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
78% confidence
Finding

The instruction to output only the consulting advice body, combined with the rest of the document being written in English but oriented around a fixed presentation style, provides no explicit user option for language or locale preference. Under the policy, skills should not implicitly force a single language/locale without opt-in or clear justification.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.