Back to skill

Security audit

DNS

Security checks for vulnerabilities and agentic risk

Overview

This is a read-only DNS guidance skill with some overly broad trigger wording but no hidden execution, persistence, credential use, or destructive behavior.

Install only if you want DNS configuration guidance. Be aware the skill may activate on broad words like 'configure' or 'correctly'; prefer invoking it for explicit DNS topics such as records, TTL, SPF, DKIM, DMARC, CAA, nameservers, or migration planning.

Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (2)

Vague Triggers

High
Confidence
91% confidence
Finding
The trigger keywords are extremely broad and generic, making accidental activation likely during unrelated conversations. In an agent environment, overbroad activation can cause the skill to inject DNS-specific guidance into contexts where it was not requested, increasing the chance of confusing actions, unintended command suggestions, or mis-scoped handling of user requests.

Vague Triggers

High
Confidence
89% confidence
Finding
The repeated trigger section reinforces vague activation without defining when the skill should or should not run. This increases the probability of unintended invocation and cross-context interference, especially in multi-skill agents where generic words like 'correctly' or 'configure' are common in ordinary requests.

Static analysis

No suspicious patterns detected.