Back to skill

Security audit

Freelance Autobot

Security checks for vulnerabilities and agentic risk

Overview

The skill clearly aims to automate freelance applications, but it can trigger live third-party proposal submissions without enough guardrails or confirmation requirements.

Review carefully before installing or using live mode. Use dry-run first, confirm exactly which accounts and platforms it will access, and do not allow automatic proposal submission unless you are comfortable with possible account activity, duplicate or low-quality submissions, and reputation impact.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Findings (1)

Missing User Warnings

Medium
Confidence
96% confidence
Finding
The skill explicitly supports auto-submitting proposals to third-party platforms and logging activity to a local file, but the description does not prominently warn users that running the non-dry-run command performs real external actions. This can cause unintended account activity, spammy submissions, reputation damage, and unexpected local data writes if a user assumes the skill is only informational or analysis-only.

Static analysis

No suspicious patterns detected.