Back to skill

Security audit

improve-hn-karma

Security checks for vulnerabilities and agentic risk

Overview

This markdown-only skill helps draft Hacker News comments for manual posting, with engagement and privacy concerns but no hidden code, credential use, persistence, or automatic posting.

Before installing, understand that this skill is designed to optimize public Hacker News engagement. Use it only for authentic comments you stand behind, avoid spam or coordinated reputation gaming, and consider omitting usernames or long quotes from the saved plan unless they are necessary.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (2)

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
88% confidence
Finding

The trigger phrases are unusually broad and optimized around engagement manipulation, such as "generate HN karma" and "write HN posts," which can activate the skill for generic writing requests unrelated to an informed, bounded workflow. In this context, overbroad invocation increases the chance the agent is steered into deceptive social-engineering style content generation or unsolicited platform-gaming behavior without clear user intent checks.

Content

No source excerpt is available for this finding.

Missing User Warnings

Low
Category
Not specified by scanner
Confidence
80% confidence
Finding

The skill instructs the system to collect usernames and quoted comment text from third-party Hacker News users, then reuse that material in an output plan, but it provides no privacy or data-handling warning to the user. Although HN data is public, systematically extracting and repackaging identities and content for targeted engagement increases privacy and misuse risk, especially when combined with a workflow explicitly designed to influence discussions and optimize account reputation.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.