Back to skill

Security audit

Industry Briefing

Security checks for vulnerabilities and agentic risk

Overview

This skill is a simple public-news briefing template and does not install code, request credentials, or create persistence.

Install only if you want your agent to use web search to assemble current briefings. For sensitive business, legal, financial, or fast-moving topics, review the cited sources and treat the output as a summary rather than advice.

Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (1)

Vague Triggers

Medium
Confidence
86% confidence
Finding
The trigger phrase "Latest news about [company/topic]" is broad enough that the skill may be invoked for generic news queries where a more appropriate tool or workflow should handle the request. This can cause unintended skill activation and over-collection or synthesis of web content, but it does not by itself introduce code execution, privilege escalation, or data exfiltration.

Static analysis

No suspicious patterns detected.