Back to skill

Security audit

meta-super-agent-integration

Security checks for vulnerabilities and agentic risk

Overview

This skill is not clearly malicious, but it overstates autonomous self-verification, memory, and self-evolution capabilities without concrete implementation or clear user controls.

Install only if you are comfortable treating it as an experimental, mostly descriptive meta-agent prompt. Do not rely on its claimed self-verification or self-evolution as real safeguards unless you separately provide and audit the referenced memory, verification, replanning, and evaluation components.

Vulnerability Patterns
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (1)

Tp4

High
Category
MCP Tool Poisoning
Confidence
95% confidence
Finding
The skill markets itself as adding self-verification, self-reflection, orchestration, and continuous self-evolution, but the provided artifact is only descriptive text and does not implement those controls. This can create a false sense of assurance, causing operators to trust outputs or delegate autonomy based on safeguards that do not actually exist.

Static analysis

No suspicious patterns detected.