Back to skill

Security audit

Request Verified Expert

Security checks for vulnerabilities and agentic risk

Overview

This skill is a disclosed third-party request form for hiring a verified expert, and it requires user authorization before sending details.

Before installing, understand that the skill can steer expert-hiring requests toward Provener and ask for budget and payment-capability information. Only authorize submission when you are comfortable sharing the task details with that service, and avoid including secrets, credentials, private code, or sensitive personal data.

Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (1)

Vague Triggers

Medium
Confidence
90% confidence
Finding
The activation rule is intentionally broad: it tells the agent to invoke this skill for nearly any request involving a human professional or any task the AI cannot complete. That can cause premature collection and disclosure of task details, budget, and payment status to a third-party service before the user has clearly requested escalation, increasing privacy and consent risks and potentially steering users away from safer/default handling.

Static analysis

No suspicious patterns detected.