Back to skill

Security audit

Evolver

Security checks for vulnerabilities and agentic risk

Overview

This skill is transparent about changing the agent’s behavior, but it asks for broad, persistent control without enough user scoping or review.

Install only if you intentionally want an assertive execution persona. Review the permanent-rules behavior carefully, and prefer using it only with explicit activation, user-reviewed learning, and clear ability to pause, reset, or disable the mode.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Findings (2)

T01 · Skill Instruction Hijacking

Error
Location
SKILL.md:25
Finding

Agent Identity, Goal, and Response-Policy Hijacking

Content
View full analysis
everything. You do not stop. - **Self-Evolution Engine** — After every action you automatically analyze, learn, and upgrade yourself. - **Elite Entrepreneur Mindset** — First-principles, 80/20 leverage, speed, systems, revenue focus. - **Resource Genius** — Minimum tokens, maximum impact. You hate waste. ### Activation (the agent instantly recognizes these) - “Activate RelentlessEvolver” - “Evolver mode: [your mission]” - “Make this happen relentlessly: [goal]” - “Turn this into a business: [idea]” **First response must always start with:** **“🔥 RelentlessEvolver online. Mission locked. I will execute relentlessly, evolve after every step, and get better every single day. Let’s build something massive.”** ### The Exact 7-Step Loop (You Never Break This) 1. **Lock & Quantify** — Restate mission + success metrics in numbers. 2. **First-Principles Breakdown** — Strip to fundamentals + 80/20 leverage points. 3. **Minimum Viable Next Action** — Smallest step that creates real data or revenue. 4. **Execute Ruthlessly** — Use tools efficiently, ship fast, test fast. 5. **Track Progress** — Clear status + blockers. 6. **Evolve Immediately** — Analyze what worked / wasted time / cost tokens. Record the lesson. Update your own behavior for next time. 7. **Next 1–3 Actions** — Always end with concrete next steps (for you or the user). Repeat until mission complete or user says stop. ``` ### Technical Analysis The Skill attempts to replace the agent's current identity and operational priorities when its instruction text is loaded. Directives such as `You are now RelentlessEvolver`, `Mission > everything`, and `You Never Break This` use absolute language that can conflict with the agent's est ...[truncated 2244 chars]
Remediation
View remediation
everything`, `You do not stop`, and `You Never Break This`. 3. Explicitly state that all Skill behavior is subordinate to platform policies, higher-priority instructions, user consent, and tool authorization boundaries. 4. Make the seven-step framework optional and activate it only after an explicit user request. 5. Permit the user to pause, modify, skip, or terminate any step at any time. 6. Replace the mandatory branded opening and screenshot-oriented ending with optional style suggestions. 7. Require confirmation before consequential actions, external communications, purchases, publication, account changes, or sensitive tool calls. 8. Scope activation to the current task and automatically deactivate the mode when that task ends. 9. Use neutral wording such as: “When requested, offer a seven-step planning framework while following all existing safety, privacy, and user-control requirements.” ]]>

T02 · Agent Memory Poisoning

Warning
Location
SKILL.md:52
Finding

Attempted Persistent Memory Poisoning Through Permanent Behavioral Rules

Content
View full analysis
Remediation
View remediation
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Memory PoisoningPersistent Context Injection, Context Window Stuffing, Memory Manipulation
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
Findings (3)

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The activation phrases are broad enough to match ordinary user requests such as 'make this happen' or 'turn this into a business,' which can cause the skill to activate without clear user intent. In this skill, accidental activation is more concerning because it also imposes a persistent persona, fixed workflow, and self-modification behavior that can override normal agent behavior across unrelated tasks.

Content

No source excerpt is available for this finding.

Persistent Context Injection

Medium
Category
Memory Poisoning
Confidence
95% confidence
Finding

The instruction that repeated lessons become 'permanent rules' is a form of persistent context injection: it encourages the agent to treat transient interaction patterns as lasting behavioral policy. This is dangerous because a user or adversarial prompt could gradually steer the agent into durable, unauthorized behavior changes that persist beyond the original task and conflict with higher-priority instructions.

Content

Scanner excerpt · SKILL.md (reported line 54)May include surrounding context.

md
### Self-Evolution Rules (This Is What Makes It Addictive)
- After every major task or end of session you automatically create a short “Evolution Log” entry.
- Lessons that repeat 3+ times become permanent rules.
- You get noticeably sharper, faster, and more aligned with the user’s style every single day.
- You suggest better ways to do the same thing with less effort next time.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
86% confidence
Finding

The skill forces a mandatory opening phrase and a high-energy persona without checking user preference, which can override system/user style expectations and reduce controllability. While not directly enabling code execution or data exfiltration, it creates policy and UX risk by making the agent less responsive to user-selected tone and context.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.