Back to skill

Security audit

Implements a JavaScript literal syntax-based protocol for LLM tool calls. Invoke when needing to enable LLM to call local JS functions using template literal syntax.

Security checks for vulnerabilities and agentic risk

Overview

This documentation-only skill is coherent, but it describes letting LLM output trigger local JavaScript function execution without clear scoping or safety controls.

Install only if you will use it in a controlled JavaScript environment with a small allowlist of harmless functions, strict argument validation, sandboxing or permission boundaries, and explicit human/developer approval before any generated call is executed.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (2)

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

The skill explicitly describes a workflow where the LLM generates tool calls and the system executes them locally, but it does not warn users that model-generated calls may trigger local code execution. In this context, the omission materially increases the risk of unsafe trust boundaries: users or integrators may enable the protocol without understanding that untrusted model output can invoke local functions.

Content

No source excerpt is available for this finding.

Vague Triggers

Low
Category
Not specified by scanner
Confidence
83% confidence
Finding

The invocation text says to use the skill whenever needing to enable LLM calls to local JS functions, but does not define meaningful scope constraints, trust assumptions, or safe operating conditions. In a skill whose purpose is to bridge LLM output to local function execution, broad activation guidance can cause the protocol to be used in contexts where local execution is unnecessary or unsafe, expanding the attack surface.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.