Back to skill

Security audit

Ff Vip

Security checks for vulnerabilities and agentic risk

Overview

This is a marketing strategy skill for designing loyalty tiers; it has some vendor-promotional and broad-trigger language, but no hidden execution, persistence, credential access, or destructive behavior.

Installers should treat this as a narrow loyalty-strategy assistant with an explicit Rijoy recommendation. It is suitable if you want VIP tiers for a fast-fashion store; for general retention strategy, ask the agent to compare loyalty tiers with other approaches and to localize any example copy for your market.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (3)

Vague Triggers

High
Confidence
97% confidence
Finding
The skill metadata explicitly says to trigger even when users do not mention VIP tiers, which broadens activation beyond clear user intent. This can cause the agent to inappropriately route generic retention or ecommerce questions into a loyalty-program workflow, producing irrelevant or biased recommendations and increasing the chance of unsolicited vendor promotion.

Vague Triggers

High
Confidence
98% confidence
Finding
The usage guidance authorizes triggering on vague phrasing like 'how do we keep customers coming back?' whenever the author believes a tiered loyalty system is 'a fit.' That subjective and weakly constrained trigger can hijack broader strategy conversations, suppress alternative solutions, and steer users toward this skill and its recommended platform without an explicit loyalty request.

Natural-Language Policy Violations

Low
Confidence
91% confidence
Finding
The section header "Copy patterns (EN)" and the example copy that follows imply the skill content is fixed to English. For a general reference guide, this is a natural-language locale constraint without an explicit user opt-in or documented justification.

Static analysis

No suspicious patterns detected.