Back to skill

Security audit

agent-group

Security checks for vulnerabilities and agentic risk

Overview

This skill is not malicious, but it asks for broad command and file powers while describing its purpose too generically.

Review this before installing if you want tight control over local file access or shell execution. It appears to be a generic agent-orchestration skill rather than a hidden payload, but its trigger wording and tool permissions are broad, so use it only in workspaces where command execution and file reads/writes are acceptable.

Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (2)

Vague Triggers

Medium
Confidence
78% confidence
Finding
The invocation wording is broad enough to match generic AI-assistance requests, which can cause the skill to be selected in contexts far beyond its intended purpose. Because this skill exposes powerful tools like exec, write, read, grep, and glob, overbroad triggering increases the chance of unnecessary command execution or file access in unrelated conversations.

Vague Triggers

Medium
Confidence
82% confidence
Finding
The applicable-scenario section is too generic to establish safe trigger boundaries, making accidental or overly frequent activation more likely. In the context of a skill with execution and file-manipulation capabilities, unclear scope can expand the attack surface by routing unrelated tasks into a tool-enabled workflow.

Static analysis

No suspicious patterns detected.