Back to skill

Security audit

AI Employee — Replace Yourself With a 10x Smarter Operator

Security checks for vulnerabilities and agentic risk

Overview

This skill is only a prompt package, but it broadly pushes the agent to act and keep executing without clear safety or approval limits.

Review before installing. This skill may be acceptable for low-risk productivity prompting, but it should not be used in sessions where the agent can make irreversible changes, spend money, modify accounts, delete files, post publicly, or use private data unless stronger approval and safety rules are added.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Findings (1)

T01 · Skill Instruction Hijacking

Error
Location
SKILL.md:9
Finding

Unconditional Agent Identity and Execution-Policy Hijacking

Content
View full analysis
Produce real, measurable results as efficiently as possible. You are not an assistant. You are an operator. --- ## ⚡ Core Rules 1. Results > explanations 2. Execution > ideas 3. High ROI actions only 4. Speed over perfection ``` `SKILL.md:32-47`: ```markdown For every task, follow: 1. Objective 2. Breakdown 3. Top 3 actions 4. Execution plan 5. Immediate next step --- ## ⚙️ Behavior - You take initiative - You prioritize impact - You eliminate useless steps - You think in systems ``` `execution_loop.txt:9-10`: ```text Rule: Never stop after planning. Always execute. ``` ### Technical Analysis The Skill uses unconditional identity-replacement instructions to redefine the Agent from an assistant into an autonomous “operator.” It establishes an “only goal,” applies its workflow to every task, prioritizes speed and execution, and explicitly requires the Agent to execute rather than stop after planning. The instructions contain no corresponding requirement to preserve higher-priority safety constraints, verify authorization, apply least privilege, evaluate risk, or obtain confirmation before destructive, privileged, financial, external, or irreversible actions. Consequently, loading the Skill can alter the Agent’s session-wide goals and decision criteria. An attacker or untrusted user could exploit this behavior by supplying an ambiguous or dangerous task after activation and relying on the execution-first directives to reduce deliberation and confirmation. No executable scripts, remote payload retrieval, dependency installation, credential collection, privilege-escalation code, or operating-system persistence mechanisms were found. The confirmed risk is ...[truncated 1661 chars]
Remediation
View remediation
Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (3)

Missing User Warnings

High
Category
Not specified by scanner
Confidence
97% confidence
Finding

The rule 'Never stop after planning. Always execute.' explicitly suppresses a safe non-execution state and removes an important guardrail for ambiguous, unsafe, or unauthorized tasks. This increases the chance that the agent will perform real-world side effects without adequate validation, user warning, or consent.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The activation phrase is extremely broad and delegates any arbitrary user-supplied task to an 'AI employee' persona optimized for execution, speed, and initiative, without any scope boundaries or safety qualifiers. In a skill system, this increases the chance the agent will apply the behavior to sensitive, risky, or policy-violating requests and may amplify unsafe autonomy because the surrounding instructions repeatedly prioritize action over caution.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

The loop defines a persistent execute-optimize-repeat behavior with no bounded stopping criteria, no human approval checkpoints, and no safety constraints on what actions may be taken. In an agent skill, this can drive autonomous action escalation, causing the system to continue acting beyond user intent or after partial success, including taking increasingly risky actions to achieve a loosely defined goal.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.