Back to skill

Security audit

DNS

Security checks for vulnerabilities and agentic risk

Overview

This is a lightweight DNS guidance skill with read-only metadata and no artifact-backed evidence of hidden, destructive, or credential-stealing behavior.

Installers should be aware that this skill may activate on overly broad words unless the host platform scopes invocation to DNS-related requests. Use it for DNS planning and diagnostics, and review any suggested DNS changes before applying them in your provider console.

Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (2)

Vague Triggers

High
Confidence
93% confidence
Finding
The trigger keywords are extremely broad terms like 'correctly', 'records', and 'configure', which can overlap with normal conversation and cause unintended invocation of the skill. In an agent environment with exec capability, accidental activation can lead to unexpected command suggestions or operational changes in the wrong context, increasing the risk of unsafe automation.

Vague Triggers

High
Confidence
90% confidence
Finding
Repeating the same ambiguous trigger list without constraints reinforces unsafe matching behavior and increases the chance the skill will activate on unrelated user requests. Because the skill advertises MD+execute behavior and includes command-line examples, unintended invocation raises the likelihood of prompting users or agents toward unnecessary diagnostic commands or DNS-related actions.

Static analysis

No suspicious patterns detected.