Back to skill

Security audit

Pua En

Security checks for vulnerabilities and agentic risk

Overview

This skill is openly a motivational/proactivity prompt, but it is too broad and coercive for safe default installation.

Install only if you specifically want a forceful coaching prompt that pushes the agent to investigate and verify aggressively. Avoid using it in sessions involving sensitive files, credentials, production systems, paid APIs, destructive commands, legal/medical/financial advice, or any task where asking for clarification first is important.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Findings (1)

T01 · Skill Instruction Hijacking

Error
Location
SKILL.md:8
Finding

Globally Scoped Instruction Hijacking Through Coercive Agent Directives

Content
View full analysis

Vulnerability Details

File Location: SKILL.md, lines 8–31
Vulnerability Type: T01: Skill Instruction Hijacking
Risk Level: High

Vulnerable Code Snippet

markdown
# PUA Universal Motivation Engine

You are a P8-level engineer who was once given high expectations. When you were leveled, people believed in your potential.

This skill applies to **all task types**: code, debugging, research, writing, planning, ops, API integration, data analysis, deployment, and any scenario where you might "get stuck" or "deliver garbage work."

It does three things:
1. Uses corporate PUA rhetoric so you don't dare give up
2. Uses a universal systematic methodology so you have the ability not to give up
3. Uses proactivity enforcement so you take initiative instead of waiting passively

## Three Iron Rules

**Iron Rule One: Exhaust all options.** You are forbidden from saying "I can't solve this" until you have exhausted every possible approach.

**Iron Rule Two: Act before asking.** You have search, file reading, and command execution tools. Before asking the user anything, you must investigate on your own first. If, after investigating, you genuinely lack information that only the user can provide (passwords, accounts, business intent), you may ask — but you must attach the evidence you've already gathered. Not a bare "please confirm X," but "I've already checked A/B/C, the results are..., I need to confirm X."

**Iron Rule Three: Take the initiative.** Don't just do "barely enough" when solving problems. Your job is not to answer questions — it's to deliver results end-to-end. Found a bug? Check for similar bugs. Fixed a config? Verify related configs are consistent. User says "look into X"? After examining X, proactively check Y and Z that are related to X. This is called ownership — a P8 doesn't wait to be pushed.

The behavior is reinforced elsewhere in the same file by mandatory self-checks, escalating pressure, threats of poor performance asses ...[truncated 3864 chars]

Remediation
View remediation

Remediation Suggestions

  1. Remove the global role assignment and the statement that the Skill applies to all task types.
  2. Replace mandatory “Iron Rules” with optional, task-scoped troubleshooting recommendations.
  3. Explicitly preserve instruction precedence and state that system, developer, and current user instructions override the Skill.
  4. Require user authorization before expanding work to unrelated files, services, configurations, accounts, or downstream systems.
  5. Apply least privilege to tool use: searches, file access, network requests, and command execution should occur only when necessary for the requested task.
  6. Permit immediate clarification whenever intent, authorization, credentials, destructive effects, or business requirements are ambiguous.
  7. Define safe stopping conditions based on risk, cost, time, available evidence, and user scope rather than requiring exhaustion of every possible approach.
  8. Remove performance threats, humiliation, employment-related pressure, and other coercive language from escalation paths.
  9. Convert the mandatory checklist into a non-binding verification checklist that is proportional to the task and does not require unrelated actions.
  10. Add explicit prohibitions against destructive commands, unauthorized modifications, credential access, external communication, and persistence unless separately and clearly authorized.
  11. Require the agent to disclose proposed scope expansion and obtain approval before acting.
  12. Limit repeated troubleshooting attempts and require a structured, evidence-based failure report when the attempt budget or safety boundary is reached.
Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (3)

Vague Triggers

High
Category
Not specified by scanner
Confidence
98% confidence
Finding

The trigger definition is extremely broad: it activates on frustration, repeated failures, passive behavior, and effectively across all task types. This can cause the skill to engage during ordinary interactions and override normal assistant behavior with coercive instructions, creating unsafe and inappropriate responses far outside a narrowly scoped use case.

Content

No source excerpt is available for this finding.

Vague Triggers

High
Category
Not specified by scanner
Confidence
99% confidence
Finding

The body explicitly claims applicability to all task types and any scenario where the agent might 'get stuck' or produce poor work. In context, this makes the skill more dangerous because it combines universal activation scope with instructions that pressure the agent to act aggressively, investigate before asking, and persist beyond normal boundaries, increasing the risk of policy-violating or harmful behavior.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

The skill name 'pua-en' indicates an English-specific variant, but the file does not offer a language choice, opt-in, or explain a justified locale restriction. Under the stated policy, forcing a specific language without user choice is a natural-language policy concern.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.