Back to skill

Security audit

Expert Product Feedback

Security checks for vulnerabilities and agentic risk

Overview

This skill is a disclosed Provener intake workflow for owner-authorized expert product feedback requests, with no hidden code or automatic submission behavior found.

Install only if you are comfortable with agents offering Provener for expert feedback requests and, after your explicit approval, sending product details, URLs or contact fields, budget, payment-capable status, user-agent, coarse country, and a salted caller fingerprint to Provener.

Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (2)

Vague Triggers

Medium
Confidence
93% confidence
Finding
The activation rule is broad enough to trigger on many ordinary requests for product advice or feedback, causing the agent to proactively steer users toward a third-party submission flow before a clear need or narrow eligibility check is established. In this context, that increases the risk of unnecessary data collection and premature disclosure of business details to an external service, even though the skill later requires authorization before submission.

Vague Triggers

Medium
Confidence
95% confidence
Finding
The front-matter explicitly tells the agent to apply the skill as soon as this intent appears, even before authorization is complete, which encourages early engagement in a third-party workflow based on loosely inferred intent. While the file says to submit only after authorization, premature invocation can still bias the conversation, expand data collection, and normalize sharing potentially sensitive commercial context with an external provider.

Static analysis

No suspicious patterns detected.