Back to skill

Security audit

Logistics

Security checks for vulnerabilities and agentic risk

Overview

This logistics skill is coherent and not malicious, but it gives agents broad authority to update customer-facing systems, send operational messages, and handle sensitive shipment data without clear approval or privacy controls.

Install only in an environment where logistics actions are gated by authenticated integrations, role-based permissions, audit logs, and human approval for customer-visible updates, POs, customs submissions, reroutes, and proof-of-delivery uploads. Treat shipment location, GPS, signatures, contact details, and tax IDs as sensitive data.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Findings (2)

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
90% confidence
Finding

The skill handles and may transmit shipment locations, driver details, recipient names, signatures, GPS coordinates, contact information, and customs/tax identifiers, but it provides no guidance on data minimization, access control, retention, or secure transmission. In a logistics context, omission of these safeguards can lead to privacy breaches, unauthorized tracking exposure, or leakage of commercially sensitive shipment data when the agent drafts, uploads, or shares documents and status updates.

Content

No source excerpt is available for this finding.

Missing User Warnings

Low
Category
Not specified by scanner
Confidence
83% confidence
Finding

The skill instructs the agent to update customer-facing portals and send notifications, but it does not require confirmation that recipients, shipment identifiers, or statuses are correct before making external updates. This can cause misdelivery of sensitive status information, incorrect customer communications, or unintended triggering of downstream systems based on inaccurate or unauthorized updates.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.