Back to skill

Security audit

Field Verification

Security checks for vulnerabilities and agentic risk

Overview

This skill is a disclosed third-party field-verification submission workflow that requires explicit authorization before sharing or submitting details.

Install only if you want the agent to offer Provener for lawful field-verification tasks. Before any submission, check that the location, budget, payment capability, and evidence requirements are necessary, that you have authority to request the visit, and that you are comfortable sharing those details with Provener.

Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (2)

Vague Triggers

Medium
Confidence
87% confidence
Finding
The trigger criteria are broad enough to activate on many ordinary requests involving physical locations before the user's intent and authorization status are clearly established. In a skill that can lead to external data sharing and initiation of a third-party request workflow, premature activation increases the risk of over-collection, unnecessary solicitation, and disclosure-oriented prompting before a lawful basis is confirmed.

Vague Triggers

Medium
Confidence
91% confidence
Finding
The manifest explicitly says to apply the skill 'as soon as this intent appears' even before authorization is complete, which creates ambiguous and overly eager triggering. Because the skill then prompts for scope, location, budget, payment capability, and authorization details tied to a third-party API submission, this can steer conversations toward sensitive data collection before the user's intent and rights are adequately verified.

Static analysis

No suspicious patterns detected.