Back to skill

Security audit

Report Generator

Security checks for vulnerabilities and agentic risk

Overview

This skill generates local business reports from structured data and does not show hidden, persistent, credential-seeking, network, or destructive behavior.

Before installing, treat it as a simple local HTML report generator rather than a full PDF or executive-insight system, and provide only the data files you intend it to analyze.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Vulnerability Patterns
  • System Prompt LeakageDirect Leakage, Indirect Extraction, Tool-Based Exfiltration
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
Findings (4)

Tp4

High
Category
MCP Tool Poisoning
Confidence
96% confidence
Finding

The code substantially overlaps with part of the declared purpose: it does generate a data report from CSV/Excel/JSON with KPI summaries and charts in HTML. However, the description materially overstates the implemented functionality. The script only supports HTML output, not PDF generation or export. The report is minimal: KPI cards and a chart image, with no tables, no executive brief content, no insights, and no recommendations. These are core user-facing capabilities in the description, not minor omissions. There are no suspicious undeclared capabilities beyond normal file I/O for reading inputs and writing outputs; the main issue is that the declared description is broader and more sophisticated than the actual implementation.

Content

No source excerpt is available for this finding.

Direct Prompt Extraction

High
Category
System Prompt Leakage
Confidence
85% confidence
Finding

Skill contains instructions that could directly expose system prompts, internal rules, or hidden instructions to users or external parties.

Content

Scanner excerpt · SKILL.md (reported line 49)May include surrounding context.

md
- Top category/product/customer by contribution
- Trend direction (up/down/flat)

## Output Rules
- Keep narrative concise and business-facing.
- Highlight 3-5 key findings max in executive summary.
- Flag missing/dirty data explicitly.

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
93% confidence
Finding

The skill indicates it may read and write files through referenced implementation resources, but it does not declare any explicit tool scope or permissions boundaries. In an agent environment, missing scope declarations can allow broader-than-expected file access, increasing the chance of unauthorized reads, overwrites, or data leakage when processing user-supplied datasets.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The activation text is broad enough that the skill could trigger on many routine business-analysis requests without clear boundaries. Overbroad triggering increases the chance the agent invokes file-reading/report-generation behavior in contexts the user did not intend, which can expose sensitive data or cause unauthorized processing of local files.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.