Back to skill

Security audit

Phy Platform Rules Engine

Security checks for vulnerabilities and agentic risk

Overview

This skill is a local social-post checker that reads user-provided draft text and reports platform-specific warnings, with no evidence of hidden execution, network access, credential use, persistence, or posting automation.

Install only if you want a local heuristic checker for draft social posts. Review its recommendations critically, especially advice about platform algorithms, reach multipliers, link placement, and shadowbans, and do not use it to evade moderation, spam controls, or platform rules.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
Findings (5)

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
70% confidence
Finding

Without declared permissions the skill's intent is opaque and cannot be validated.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
89% confidence
Finding

The manifest description says the tool 'Scans any draft post' and presents a broad capability description, but it does not specify concrete trigger phrases, scope limits, or exclusion conditions. In a markdown/manifest context, this kind of generic wording can overlap with many normal requests about drafting or checking posts and may cause unintended invocation.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
88% confidence
Finding

This skill is explicitly framed around exploiting 'invisible rules,' avoiding shadowbans, and maximizing distribution using claimed algorithmic penalties and multipliers. Without a warning or policy boundary, it can encourage platform-gaming, deceptive optimization, or advice that nudges users toward evasion of moderation and ranking systems.

Content

No source excerpt is available for this finding.

Vague Triggers

Low
Category
Not specified by scanner
Confidence
80% confidence
Finding

The markdown provides command examples but does not define when the skill is intended to activate versus when general writing, editing, or social-media advice requests should not use it. For SQP-1, the absence of explicit scope constraints or negative examples can make activation conditions ambiguous.

Content

No source excerpt is available for this finding.

Intent-Code Divergence

Low
Category
Not specified by scanner
Confidence
84% confidence
Finding

The module documentation says the checker outputs PASS/WARN/FAIL per rule with exact fix suggestions, implying every rule result includes remediation guidance. In code, multiple PASS results and the unknown-platform error path create RuleResult objects without a fix string, so the documented output contract is broader than the actual behavior.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.