Back to skill

Security audit

Tech Scout

Security checks for vulnerabilities and agentic risk

Overview

This skill is a disclosed daily research digest, but users should understand that it may run scheduled web searches and save digest state locally.

Install only if you are comfortable with an agent using your configured project keywords to query external services and saving daily digests plus seen URLs under state/. Configure narrow keywords, avoid confidential internal project names, and confirm any automated schedule before enabling it.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (4)

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

The skill directs searches across X, YouTube, Reddit, GitHub, and real-time web search providers but does not clearly warn that user interests, project keywords, or prompts may be transmitted to third-party services. This creates a privacy risk because active-project context can reveal sensitive research priorities, commercial plans, or internal topics.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The manual triggers are broad enough to match ordinary conversational requests like general research or status-check prompts, which can cause the skill to activate without clear user intent. In this skill, unintended activation is meaningful because it initiates multi-source internet searches and may create persistent digest files, expanding both privacy and side-effect risk.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The skill instructs persistent writes to local state files and output digests without clearly warning the user that local state will be modified. Silent persistence can surprise users, leak prior activity across sessions, and create unwanted retention of browsing and project-interest data.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
75% confidence
Finding

The description says the agent runs automatically each morning before the user's first session, and later sections prescribe a 06:00-07:00 local-time schedule. This imposes a specific time/locale convention without indicating that users can choose a different schedule or opt in.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.