Back to skill

Security audit

meta-agent-team-orchestration

Security checks for vulnerabilities and agentic risk

Overview

The skill does not show theft or destruction, but it overstates advanced self-verification and self-evolution capabilities that are not actually implemented in the artifact.

Install only if you are comfortable treating this as a lightweight orchestration prompt plus a local learner log, not as a verified autonomous safety framework. Do not rely on its claimed self-verification or self-evolution safeguards for sensitive work unless you independently add and test those controls.

Vulnerability Patterns
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (1)

Tp4

High
Category
MCP Tool Poisoning
Confidence
91% confidence
Finding
The skill markets itself as having advanced self-verification, self-reflection, orchestration, and self-evolution capabilities that are not actually implemented in the provided content. This is dangerous because operators may overtrust the skill's claimed safeguards and delegate sensitive tasks under false assumptions, reducing scrutiny and potentially causing unsafe autonomous behavior or policy bypass by omission.

Static analysis

No suspicious patterns detected.