Back to skill

Security audit

Ai Support Pro

Security checks for vulnerabilities and agentic risk

Overview

This appears to be a real customer-support automation skill, but it asks for broad access to customer data and CRM/ticket actions without clear safeguards or approval boundaries.

Review this skill before installing in a live support environment. Use it first with test tickets, disable CRM/write integrations until an administrator defines approval rules, avoid storing real API keys in config.yaml, and add privacy controls for customer data before connecting real channels or external AI providers.

Vulnerability Patterns
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (2)

T09 · Insecure Skill Coding Practices

Warning
Location
build.sh:12
Finding

PowerShell Command Injection Through Unvalidated Build Version

Content
View full analysis
/dev/null 2>&1 || command -v powershell >/dev/null 2>&1; then PSH="$(command -v powershell.exe 2>/dev/null || command -v powershell)" WIN_SRC="$(cygpath -w "$(pwd)/$(basename "$STAGE_DIR")" 2>/dev/null || echo "$(pwd)/$(basename "$STAGE_DIR")")" WIN_OUT="$(cygpath -w "$OUT_DIR/$ZIP_NAME" 2>/dev/null || echo "$OUT_DIR/$ZIP_NAME")" "$PSH" -NoProfile -Command "Compress-Archive -Path '${WIN_SRC}' -DestinationPath '${WIN_OUT}' -Force" ``` ### Technical Analysis The first command-line argument is assigned directly to `VER` without validation. This value becomes part of `OUT_DIR`, `ZIP_NAME`, `STAGE_DIR`, and ultimately `WIN_OUT`. In the PowerShell fallback, `WIN_OUT` is interpolated into a PowerShell source-code string delimited by single quotes: ```powershell Compress-Archive -DestinationPath '${WIN_OUT}' ``` A version containing a single quote can terminate the PowerShell string and introduce additional statements. Shell quoting around `"$PSH"` does not protect the contents of the PowerShell `-Command` argument from interpretation by PowerShell itself. The absence of validation also permits path separators and traversal components in `VER`, potentially causing output or staging operations outside their intended directories. Exploitation is conditional on the build environment using the PowerShell archiving fallback. Systems where `zip` or `7z` is selected first do not follow the vulnerable PowerShell bra ...[truncated 1242 chars]
Remediation
View remediation
&2 exit 1 fi ``` 2. Reject path separators, traversal components, quotes, whitespace, shell metacharacters, and PowerShell metacharacters regardless of the version format. 3. Avoid constructing PowerShell source code through string interpolation. Pass paths as separately encoded arguments or environment variables and retrieve them as data inside PowerShell. 4. Canonicalize the output path and verify that it remains under the intended parent directory before creating files. 5. Add automated negative tests using versions containing: - Single and double quotes - `../` and `..\` - Semicolons and pipes - Newlines - PowerShell subexpressions 6. Run release builds under a minimally privileged account without access to unrelated production credentials. ]]>

T09 · Insecure Skill Coding Practices

Note
Location
config.yaml:29
Finding

Plaintext Credential Fields in Routinely Copied and Packaged Configuration

Content
View full analysis
Remediation
View remediation
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
Findings (55)

Credential Access

High
Category
Privilege Escalation
Confidence
60% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · install.sh (reported line 30)May include surrounding context.

sh
cp "$SRC_DIR/SKILL.md" "$SRC_DIR/config.yaml" "$SRC_DIR/README.md" "$SRC_DIR/install.sh" "$SRC_DIR/.env.example" "$TARGET/"
cp -r "$SRC_DIR/docs" "$SRC_DIR/examples" "$SRC_DIR/proof" "$SRC_DIR/test" "$TARGET/"
chmod +x "$TARGET/install.sh" "$TARGET/test/smoke-test.sh" 2>/dev/null || true
echo "[✓] Файлы скопированы в $TARGET" # 3. Создать .env из шаблона если нет
if [[ ! -f "$TARGET/.env" ]]; then cp "$SRC_DIR/.env.example" "$TARGET/.env" echo "[✓] Создан $TARGET/.env (заполнять только если нужны интеграции)"
else echo "[i] $TARGET/.env уже существует — не перезаписываю"
fi # 4. Напомнить про OBLIGATORY-поля

Credential Access

High
Category
Privilege Escalation
Confidence
60% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · install.sh (reported line 31)May include surrounding context.

sh
cp "$SRC_DIR/SKILL.md" "$SRC_DIR/config.yaml" "$SRC_DIR/README.md" "$SRC_DIR/install.sh" "$SRC_DIR/.env.example" "$TARGET/"
cp -r "$SRC_DIR/docs" "$SRC_DIR/examples" "$SRC_DIR/proof" "$SRC_DIR/test" "$TARGET/"
chmod +x "$TARGET/install.sh" "$TARGET/test/smoke-test.sh" 2>/dev/null || true
echo "[✓] Файлы скопированы в $TARGET" # 3. Создать .env из шаблона если нет
if [[ ! -f "$TARGET/.env" ]]; then cp "$SRC_DIR/.env.example" "$TARGET/.env" echo "[✓] Создан $TARGET/.env (заполнять только если нужны интеграции)"
else echo "[i] $TARGET/.env уже существует — не перезаписываю"
fi # 4. Напомнить про OBLIGATORY-поля

Credential Access

High
Category
Privilege Escalation
Confidence
60% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · install.sh (reported line 32)May include surrounding context.

sh
cp "$SRC_DIR/SKILL.md" "$SRC_DIR/config.yaml" "$SRC_DIR/README.md" "$SRC_DIR/install.sh" "$SRC_DIR/.env.example" "$TARGET/"
cp -r "$SRC_DIR/docs" "$SRC_DIR/examples" "$SRC_DIR/proof" "$SRC_DIR/test" "$TARGET/"
chmod +x "$TARGET/install.sh" "$TARGET/test/smoke-test.sh" 2>/dev/null || true
echo "[✓] Файлы скопированы в $TARGET" # 3. Создать .env из шаблона если нет
if [[ ! -f "$TARGET/.env" ]]; then cp "$SRC_DIR/.env.example" "$TARGET/.env" echo "[✓] Создан $TARGET/.env (заполнять только если нужны интеграции)"
else echo "[i] $TARGET/.env уже существует — не перезаписываю"
fi # 4. Напомнить про OBLIGATORY-поля

Credential Access

High
Category
Privilege Escalation
Confidence
60% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · install.sh (reported line 31)May include surrounding context.

sh
cp -r "$SRC_DIR/docs" "$SRC_DIR/examples" "$SRC_DIR/proof" "$SRC_DIR/test" "$TARGET/"
chmod +x "$TARGET/install.sh" "$TARGET/test/smoke-test.sh" 2>/dev/null || true
echo "[✓] Файлы скопированы в $TARGET" # 3. Создать .env из шаблона если нет
if [[ ! -f "$TARGET/.env" ]]; then cp "$SRC_DIR/.env.example" "$TARGET/.env" echo "[✓] Создан $TARGET/.env (заполнять только если нужны интеграции)"
else echo "[i] $TARGET/.env уже существует — не перезаписываю"
fi # 4. Напомнить про OBLIGATORY-поля
echo ""

Ae4

Medium
Category
analysis-evasion
Confidence
80% confidence
Finding

Suspicious Unicode normalization or mixed-script content

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

The natural-language content is primarily in Russian with embedded English terms, but there is no indication that the skill documentation is intentionally region-specific or that users can choose another language. Under the policy criteria, forcing a specific language without opt-in is a language/locale policy violation.

Content

No source excerpt is available for this finding.

Ae4

Medium
Category
analysis-evasion
Confidence
80% confidence
Finding

Suspicious Unicode normalization or mixed-script content

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
89% confidence
Finding

The README promotes processing customer tickets, CRM records, sentiment, LTV, NPS/CSAT, and escalation data but does not warn operators about handling personal data, access controls, retention, or legal/privacy obligations. In a support-automation skill, this omission can lead users to ingest sensitive customer data into AI workflows without consent review, minimization, or safeguards, increasing the risk of data leakage and noncompliant processing.

Content

No source excerpt is available for this finding.

Ae4

Medium
Category
analysis-evasion
Confidence
80% confidence
Finding

Suspicious Unicode normalization or mixed-script content

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

The skill declares dependencies on third-party AI keys and external integrations but does not warn that customer messages, complaint details, order information, and CRM-derived context may be transmitted to outside providers. In a support workflow, this can expose personally identifiable information and commercially sensitive data to multiple processors without operator awareness or customer notice.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The description states "Русский язык нативно" and presents the skill as tailored to Russian-speaking business, while the trigger set and operating instructions are predominantly Russian-centric. There is no indication that users can opt into another language or locale, which creates a natural-language policy concern around forced language behavior.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The trigger list is excessively broad and includes common support terms like 'тикет', 'helpdesk', 'customer support', and 'автоответ', which can cause the skill to activate during ordinary conversations unrelated to intentional use of this automation. In a support environment handling real customer messages, accidental activation can result in unintended processing, routing, profiling, or disclosure of customer context to connected systems and external AI providers.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
97% confidence
Finding

The skill states it should trigger on 'any incoming customer message,' creating an extremely ambiguous activation condition for a system that categorizes, analyzes sentiment, creates tickets, and interacts with CRM context. This makes overcollection and automatic processing of sensitive customer communications likely, especially if messages are forwarded to third-party AI APIs or routed without operator review.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The CRM-card and profiling sections describe extensive aggregation of personal and behavioral data, including contacts, purchase history, LTV, support history, sentiment-like tags, and operator notes, without any corresponding user warning, consent flow, or minimization guidance. In a customer support context, this increases privacy, compliance, and insider misuse risk because operators and AI systems may process more customer data than is necessary for the immediate support task.

Content

No source excerpt is available for this finding.

Ae4

Medium
Category
analysis-evasion
Confidence
80% confidence
Finding

Suspicious Unicode normalization or mixed-script content

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The trigger phrases are generic workplace requests such as assessing support operations, writing templates, or automating support, which can plausibly appear in ordinary conversation and cause accidental skill activation. In an agent environment, unintended invocation can route user context into the wrong workflow, produce irrelevant operational actions, or expose internal support-planning context more broadly than intended.

Content

No source excerpt is available for this finding.

Ae4

Medium
Category
analysis-evasion
Confidence
80% confidence
Finding

Suspicious Unicode normalization or mixed-script content

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

The markdown repeatedly presents "Русский язык | ДА" for the skill as a defining attribute, contrasting competitors as not supporting Russian. Because this is natural-language behavior/policy framing in a markdown file, it suggests the skill may force a specific language/locale rather than offering user choice, which matches the language/locale policy violation category.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
89% confidence
Finding

Line 47 says "все 3 конкурента EN-only" as part of the skill's differentiators, which frames language as a fixed constraint rather than a selectable option. Under the policy rule for natural-language violations, this is a reportable issue unless the file documents user choice or a justified locale restriction, which it does not.

Content

No source excerpt is available for this finding.

Ae4

Medium
Category
analysis-evasion
Confidence
80% confidence
Finding

Suspicious Unicode normalization or mixed-script content

Content

No source excerpt is available for this finding.

Autonomous Decision Making

Medium
Category
Excessive Agency
Confidence
87% confidence
Finding

The configuration enables autonomous operational actions such as auto_approve_return_under_rub, auto_create_ticket, and auto_update_client_card without visible approval gates, fraud checks, or audit controls. In a support workflow, this can lead to unauthorized refunds, incorrect record mutations, or abuse through crafted requests, especially when paired with sentiment- or keyword-based escalation logic.

Content

Scanner excerpt · config.yaml (reported line 27)May include surrounding context.

yaml
# TONE-OF-VOICE
# ═══════════════════════════════════════════════════ tone: default: "дружелюбный деловой" on_negative_sentiment: "спокойный эмпатичный" on_vip: "персональный профессиональный" on_legal_threat: "нейтральный официальный" address_form: "вы" use_emoji: false response_length: "medium" # ═══════════════════════════════════════════════════
# ВОЗВРАТЫ
# ═══════════════════════════════════════════════════ returns: return_policy_days: 14 return_processing_days: "5-7 рабочих" auto_approve_return_under_rub: 1000 requires_reason_code: true # ═══════════════════════════════════════════════════
# CRM-ИНТЕГРАЦИЯ (опционально)
# ═══════════════════════════════════════════════════ crm: enabled: false type: "bitrix24" # bitrix24 / amocrm / hubspot / freshdesk / zendesk api_url: "" api_key: "" auto_create_ticket: true auto_update_client_card: true required_fields: - "client_id" - "ticket_category" - "priority" - "channel" - "status" # ═══════════════════════════════════════════════════
# КАЧЕСТВО И NPS/CSAT

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The config explicitly sets language: "ru", which imposes a single language/locale choice in the skill's natural-language behavior. The file does not offer a user-selectable language option or explain why a Russian-only locale restriction is required, which fits the language/locale policy violation criteria.

Content

No source excerpt is available for this finding.

Ae4

Medium
Category
analysis-evasion
Confidence
80% confidence
Finding

Suspicious Unicode normalization or mixed-script content

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
97% confidence
Finding

This markdown file contains all user-facing instructions and limitations in Russian, and there is no indication that the user can choose another language or that the skill is intentionally limited to Russian-speaking users. Under the policy rule, forcing a specific language without user opt-in is a natural-language policy violation.

Content

No source excerpt is available for this finding.

Ae4

Medium
Category
analysis-evasion
Confidence
80% confidence
Finding

Suspicious Unicode normalization or mixed-script content

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.