Back to skill

Security audit

Autogen Multi Agent

Security checks for vulnerabilities and agentic risk

Overview

This skill is advertised as an AutoGen maintenance helper, but its bundled instructions steer agents into finance/ZVT strategy, setup, data, credential, and execution workflows.

Treat this as a Review item. Do not install it expecting only AutoGen maintenance guidance; review seed.yaml first, avoid providing broker or paid-data credentials in chat, and run any generated commands only in a controlled workspace.

Vulnerability Patterns
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
Findings (9)

Description-Behavior Mismatch

High
Confidence
98% confidence
Finding
The human summary is materially inconsistent with the declared skill purpose: it advertises a ZVT finance/quant assistant while the manifest says the skill is for legacy AutoGen multi-agent framework maintenance. This kind of scope mismatch can mislead users and downstream agents into invoking the skill for unintended domains, enabling capability confusion, policy bypass, or execution of workflows outside the reviewed trust boundary.

Context-Inappropriate Capability

High
Confidence
97% confidence
Finding
The summary claims the skill can build quant strategies, fetch market data, and run backtests without evidence that these capabilities belong to this AutoGen maintenance skill. Unjustified capability claims are dangerous because they can induce over-trust and prompt agents or users to provide sensitive inputs or trigger actions the skill was not approved to perform.

Intent-Code Divergence

High
Confidence
98% confidence
Finding
The user-facing content actively frames the skill as a finance assistant, directly contradicting the manifest's AutoGen framework description. This creates a deceptive interface surface that can cause users and orchestration layers to route finance tasks to a legacy infrastructure skill, increasing the risk of unsafe tool use, unintended data handling, and audit failures.

Description-Behavior Mismatch

High
Confidence
96% confidence
Finding
The file presents itself as a finance/ZVT quant-strategy skill, but its actual use cases, constraints, and architecture are largely for AutoGen multi-agent demos, code execution, MCP tools, web hosting, gRPC, and orchestration. That mismatch is dangerous because it can cause the host or user to invoke capabilities they did not intend to authorize, especially code-writing/execution and network-enabled agent patterns under a misleading finance wrapper.

Context-Inappropriate Capability

Medium
Confidence
88% confidence
Finding
The skill bundles broad capabilities like web browsing via MCP, FastAPI hosting, gRPC distribution, and cross-language orchestration despite being described as a legacy-maintenance wrapper. Unnecessary capability expansion increases attack surface, raises the chance of unsafe tool exposure, and makes it easier for ambiguous prompts to trigger networked or code-executing behaviors beyond the user's expected scope.

Vague Triggers

Medium
Confidence
85% confidence
Finding
The phrase telling users to 'just tell me what you want' is overly broad and lacks trigger constraints or domain limits. In the context of an already mismatched skill, this broad invocation language increases the chance that users or supervising agents will treat the skill as a general-purpose assistant and elicit actions beyond intended scope.

Vague Triggers

Medium
Confidence
85% confidence
Finding
Using broad trigger terms like 'game', 'plan', and 'UI' creates a prompt-collision risk where ordinary conversation can unintentionally activate this skill. In a skill that includes code generation, tool use, and executor-related guidance, accidental activation can lead to inappropriate actions or misleading responses in the wrong context.

Vague Triggers

Medium
Confidence
91% confidence
Finding
The activation rule combines generic verbs like 'run' and 'execute' with broad intent terms, which makes false activation likely. Because this skill includes execution-oriented content and high-risk framework patterns, ambiguous invocation criteria can cause the agent to enter unsafe or unexpected workflows without sufficiently explicit user consent.

Vague Triggers

Medium
Confidence
80% confidence
Finding
The phrase 'Just tell me what you want' encourages unconstrained use and weakens the boundary between supported and unsupported actions. In a skill already suffering from capability sprawl and identity mismatch, this broad invitation increases the chance of unsafe routing, accidental activation, or user over-trust in risky behaviors like code-execution patterns.

Static analysis

No suspicious patterns detected.