Back to skill

Security audit

GK Fault Precheck

Security checks for vulnerabilities and agentic risk

Overview

This skill is a local, text-only industrial fault pre-check guide; it has some scope and safety caveats users should read, but no hidden execution, persistence, data upload, or credential use.

Install only if you want general industrial fault triage. Treat its output as preliminary guidance, not an authoritative repair procedure or safety approval; for high voltage, rotating machinery, STO/SIL, safety circuits, or uncertain symptoms, follow the equipment manual and use qualified personnel. Avoid sharing passwords, proprietary programs, or sensitive plant details because the skill does not need them.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
Findings (4)

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
87% confidence
Finding

The trigger set is broad and overlaps with common industrial troubleshooting phrases, increasing the chance that the skill activates in contexts where users did not explicitly request it. In an industrial-control context, unintended activation can surface operational guidance during safety-critical troubleshooting, potentially displacing more appropriate, context-aware instructions or causing overreliance on generic advice.

Content

No source excerpt is available for this finding.

Intent-Code Divergence

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

Lines L059-L060 state the skill only gives direction and does not provide full troubleshooting steps, parameter check items, or final code interpretation. However, lines L091, L095, L099 and especially L120-L129 give concrete step-by-step actions and parameter-related checks such as extending acceleration ramp, checking nameplate parameters, and insulation measurement. This is an active contradiction between the stated boundary and the documented behavior.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
82% confidence
Finding

Allowing symptom-only invocation without clear constraints makes activation ambiguous and increases the chance of generic advice being applied to the wrong device family or hazard profile. In ICS environments, mis-scoped troubleshooting guidance can contribute to unsafe field actions, incorrect diagnostics, or confidence in non-authoritative recommendations when equipment may involve high voltage, rotating machinery, or safety circuits.

Content

No source excerpt is available for this finding.

Intent-Code Divergence

Low
Category
Not specified by scanner
Confidence
89% confidence
Finding

Line L037 says users do not need to provide any device information, which implies such information is unnecessary. But the skill's core logic in L043, L067-L085 and the examples all depend on inputs like brand, model, indicator state, or alarm code to classify faults. This is a documentation-level contradiction about required input context.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.