Back to skill

Security audit

Data Analyst Agent

Security checks for vulnerabilities and agentic risk

Overview

This is a documentation-only publishing data-analysis skill with disclosed analytics behavior and no bundled code or hidden execution path.

Review whether you want a skill that may be invoked for general data-report requests; otherwise its described behavior is proportionate for publishing analytics. If connected to real platform accounts later, ensure collection is user-authorized, scoped, and does not store personal reader data.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (2)

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

The trigger description is broad enough to match common tasks like generating data reports or analyzing feedback, which can cause the skill to activate outside its intended scope. In a multi-agent system, over-broad routing can expose unrelated user data or cause this agent to collect/process platform data when a narrower, safer skill should have handled the request.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
88% confidence
Finding

L003 的自然语言描述整体以中文固定表述技能行为,且文档未说明是否可根据用户偏好切换语言或输出本地化内容。按规则,若技能隐含强制特定语言/locale 而无用户 opt-in 或明确合理依据,属于自然语言政策问题。

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.