Back to skill

Security audit

Foreman Pro

Security checks for vulnerabilities and agentic risk

Overview

This is a disclosed construction-foreman workflow package with local-only scripts and no evidence of hidden data theft, background persistence, or destructive behavior.

Install only if the Russian construction-foreman context matches your needs. Review or fix the shell scripts before running them, avoid putting unnecessary sensitive client/site data into config files, and verify all safety, legal, and standards-based outputs with a qualified human responsible for the actual site.

Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
Findings (11)

Description-Behavior Mismatch

High
Confidence
99% confidence
Finding
The file content clearly describes a generic software/IT project-management skill, while the manifest claims a construction-foreman capability. This is a real integrity and safety issue because users may rely on construction-specific guidance that the skill explicitly does not provide, leading to inappropriate use in safety-sensitive building workflows.

Intent-Code Divergence

High
Confidence
99% confidence
Finding
The limitations section explicitly states there is no construction specificity, no Russian support, and no adaptation to construction phases, directly contradicting the advertised foreman use case. In a construction context, this mismatch is dangerous because it can cause missing compliance steps, incorrect documentation, and unsafe operational decisions under false assumptions of suitability.

Description-Behavior Mismatch

High
Confidence
98% confidence
Finding
The file content is materially inconsistent with the declared skill purpose: it describes an ADHD-focused software project manager rather than a digital construction foreman. This can cause unsafe or misleading behavior if the wrong skill is selected, especially in operational construction contexts where documentation, safety, and work acceptance require domain-specific guidance.

Intent-Code Divergence

High
Confidence
99% confidence
Finding
The documentation explicitly states the skill is 'not for construction foremen,' directly contradicting the advertised foreman-oriented capability. In a construction workflow, this mismatch increases the risk of users relying on inapplicable process advice, potentially degrading safety, compliance, scheduling, or documentation quality.

Missing User Warnings

Medium
Confidence
94% confidence
Finding
The build script automatically executes a bundled `test/smoke-test.sh` after creating the ZIP, which means building the package also runs repository-controlled code on the builder's machine. In a skill/package supply-chain context, this is dangerous because a modified smoke test can perform arbitrary local actions, access environment secrets, or alter artifacts without explicit user consent or isolation.

Natural-Language Policy Violations

Medium
Confidence
82% confidence
Finding
Imposing a blanket 'no Russian language' constraint without user consent or operational justification can cause denial of service to legitimate users and exclusion in environments where Russian may be required. In this skill context, the restriction is especially problematic because construction coordination and safety documentation may need to support local language use to avoid misunderstanding.

Vague Triggers

Medium
Confidence
94% confidence
Finding
The trigger phrase uses a very broad natural-language prefix ('гант:'), which can be invoked unintentionally in ordinary user text rather than through a narrowly scoped command. In an agent skill that generates construction schedules and execution guidance, accidental activation could cause the system to process unrelated input as a scheduling request, creating unsafe or misleading planning output in a domain with real-world safety and cost consequences.

Vague Triggers

Medium
Confidence
89% confidence
Finding
The prompt examples use very broad trigger prefixes such as "бригада:", "приёмка:", "журнал:", and "безопасность:" without defining strict activation boundaries, allowed operations, or refusal conditions. In an agent skill, overly permissive natural-language triggers can cause the skill to activate on unintended inputs, route requests into the wrong workflow, or generate authoritative construction/safety guidance from underspecified or adversarial prompts.

Vague Triggers

Medium
Confidence
86% confidence
Finding
The trigger phrase "приёмка: штукатурка" is generic enough that it could activate on ordinary user text about plaster acceptance rather than an explicit request for this specific skill workflow. In an agent-routing context, overly broad triggers can cause unintended invocation, misrouting user requests, and incorrect generation of formal acceptance documentation without sufficient context.

Vague Triggers

Medium
Confidence
84% confidence
Finding
The phrase "закупка: остатки материалов" mixes inventory checking and procurement semantics, making it unclear what action the skill should take. This ambiguity can lead to unintended behavior such as producing purchasing recommendations or material decisions from incomplete inventory prompts, which is risky in a workflow tool tied to construction operations.

Vague Triggers

Medium
Confidence
91% confidence
Finding
The trigger "план дня" is extremely broad and overlaps with normal conversation, so it could match many unrelated daily-planning requests. In a multi-skill assistant, this raises the chance of accidental activation and disclosure or fabrication of construction-specific planning content in response to generic user intent.

Static analysis

No suspicious patterns detected.