Back to skill

Security audit

Office Hours

Security checks for vulnerabilities and agentic risk

Overview

This is a startup-diagnostic skill that asks questions, does purpose-aligned research, and saves a report, with no evidence of hidden code, persistence, or exfiltration.

Install only if you are comfortable with the agent using web search, reading product-related repository files and recent git history, and writing a diagnostic report under docs/business. Avoid using it in repositories that contain unrelated confidential plans, credentials, or sensitive customer data unless you first limit what the agent can read.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Vulnerability Patterns
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Memory PoisoningPersistent Context Injection, Context Window Stuffing, Memory Manipulation
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
Findings (5)

Memory Manipulation

High
Category
Memory Poisoning
Confidence
80% confidence
Finding

Skill manipulates agent memory, state, or stored context. Memory corruption can alter personality, override safety rules, or cause unpredictable behavior.

Content

Scanner excerpt · SKILL.md (reported line 205)May include surrounding context.

  1. What happens if we do nothing? Real pain point or hypothetical?
  2. What existing code/product already partially solves this?

Output premises as clear statements:

text
PREMISES:
1. [statement] — agree/disagree?

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The trigger phrases are very broad, covering generic requests like 'brainstorm this' or 'I have an idea.' That increases the chance the skill activates in situations where the user did not ask for an aggressive diagnostic workflow with web search, file inspection, and report writing.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

The skill says it 'produces a diagnostic report, not code,' but then instructs the agent to perform external web searches and inspect the local repository. That creates a capability mismatch: users may reasonably expect a conversational startup diagnostic, while the skill silently expands scope into network access and local data access.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The skill directs the agent to save a report to docs/business/office-hours-report.md without warning the user or obtaining consent. Silent file creation/modification can surprise users, overwrite existing content, or persist sensitive business analysis in a repository unintentionally.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

Medium
Category
Not specified by scanner
Confidence
88% confidence
Finding

Reading README, AGENTS.md, product files, and recent git history is broader than necessary for a generic startup-idea diagnostic. In many environments, repository files and commit history can contain sensitive internal plans, credentials, customer names, or unrelated project context that the user did not intend to expose for this task.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.