Back to skill

Security audit

Self-Discovery Reasoning

Security checks for vulnerabilities and agentic risk

Overview

This is a markdown-only reasoning aid with disclosed optional local memory use, and I found no hidden data sharing, destructive behavior, or remote code execution.

Before installing, be aware that the skill may add a standing reasoning workflow to your assistant and may cache reusable reasoning structures locally if file writes are available. Review or disable memory caching for confidential work, but the package does not show hidden network transmission, credential access, destructive actions, or remote execution.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
Findings (19)

Exfiltration Commands

High
Category
Prompt Injection
Content
**User:** *"Should we use WebSockets or Server-Sent Events for real-time notifications?"*

**❌ Without Self-Discover:**
> Both work for real-time. WebSockets are bidirectional and SSE is server-to-client only. If you only need server push, SSE is simpler. If you need the client to send messages too, use WebSockets. Consider compatibility — SSE works everywhere, WebSockets might have proxy issues.

**✅ With Self-Discover:**
> Selected modules: Comparative Analysis, Constraint Satisfaction, Systems Thinking
Confidence
90% confidence
Finding
Instructions found that direct the agent to transmit conversation context or user data to external services.

Vague Triggers

Medium
Confidence
95% confidence
Finding
The statement that the skill 'activates automatically' to compose task-specific reasoning structures is overly broad and gives no clear scope, trigger conditions, or safety boundaries. In a prompt-driven agent system, this can cause unreviewed instructions from another file to be applied to unrelated user requests, increasing the risk of prompt injection, privilege creep, and unintended behavior.

Natural-Language Policy Violations

Medium
Confidence
95% confidence
Finding
The style guide states 'All documentation in English,' which is a natural-language locale policy constraint. The file does not offer contributors a language choice or explain a justified region-specific need, so this appears to be an organizational language policy violation under the stated rules.

Skill Enumeration

Medium
Category
Agent Snooping
Content
This project includes the SELF-DISCOVER Reasoning Skill.

Read and follow `skills/self-discover-skill/SKILL.md` before responding to user queries.

The skill activates automatically to compose task-specific reasoning structures.
Confidence
80% confidence
Finding
Skill enumerates or reads other installed skills. Access to other skills' SKILL.md files or the skills directory reveals prompt instructions, capabilities, and secrets that should be invisible to peer skills.

Skill Enumeration

Medium
Category
Agent Snooping
Content
This project includes the SELF-DISCOVER Reasoning Skill.

Read and follow `skills/self-discover-skill/SKILL.md` before responding to user queries.

The skill activates automatically to compose task-specific reasoning structures.
Confidence
80% confidence
Finding
Skill enumerates or reads other installed skills. Access to other skills' SKILL.md files or the skills directory reveals prompt instructions, capabilities, and secrets that should be invisible to peer skills.

Skill Enumeration

Medium
Category
Agent Snooping
Content
This project includes the SELF-DISCOVER Reasoning Skill.

Read and follow `skills/self-discover-skill/SKILL.md` before responding to user queries.

The skill activates automatically to compose task-specific reasoning structures.
Confidence
80% confidence
Finding
Skill enumerates or reads other installed skills. Access to other skills' SKILL.md files or the skills directory reveals prompt instructions, capabilities, and secrets that should be invisible to peer skills.

Skill Enumeration

Medium
Category
Agent Snooping
Content
This project includes the SELF-DISCOVER Reasoning Skill.

Read and follow `skills/self-discover-skill/SKILL.md` before responding to user queries.

The skill activates automatically to compose task-specific reasoning structures.
Confidence
80% confidence
Finding
Skill enumerates or reads other installed skills. Access to other skills' SKILL.md files or the skills directory reveals prompt instructions, capabilities, and secrets that should be invisible to peer skills.

Skill Enumeration

Medium
Category
Agent Snooping
Content
This project includes the SELF-DISCOVER Reasoning Skill.

Read and follow `skills/self-discover-skill/SKILL.md` before responding to user queries.

The skill activates automatically to compose task-specific reasoning structures.
Confidence
80% confidence
Finding
Skill enumerates or reads other installed skills. Access to other skills' SKILL.md files or the skills directory reveals prompt instructions, capabilities, and secrets that should be invisible to peer skills.

Skill Enumeration

Medium
Category
Agent Snooping
Content
This project includes the SELF-DISCOVER Reasoning Skill.

Read and follow `skills/self-discover-skill/SKILL.md` before responding to user queries.

The skill activates automatically to compose task-specific reasoning structures.
Confidence
80% confidence
Finding
Skill enumerates or reads other installed skills. Access to other skills' SKILL.md files or the skills directory reveals prompt instructions, capabilities, and secrets that should be invisible to peer skills.

Skill Enumeration

Medium
Category
Agent Snooping
Content
This project includes the SELF-DISCOVER Reasoning Skill.

Read and follow `skills/self-discover-skill/SKILL.md` before responding to user queries.

The skill activates automatically to compose task-specific reasoning structures.
Confidence
80% confidence
Finding
Skill enumerates or reads other installed skills. Access to other skills' SKILL.md files or the skills directory reveals prompt instructions, capabilities, and secrets that should be invisible to peer skills.

Skill Enumeration

Medium
Category
Agent Snooping
Content
This project includes the SELF-DISCOVER Reasoning Skill.

Read and follow `skills/self-discover-skill/SKILL.md` before responding to user queries.

The skill activates automatically to compose task-specific reasoning structures.
Confidence
80% confidence
Finding
Skill enumerates or reads other installed skills. Access to other skills' SKILL.md files or the skills directory reveals prompt instructions, capabilities, and secrets that should be invisible to peer skills.

Skill Enumeration

Medium
Category
Agent Snooping
Content
This project includes the SELF-DISCOVER Reasoning Skill.

Read and follow `skills/self-discover-skill/SKILL.md` before responding to user queries.

The skill activates automatically to compose task-specific reasoning structures.
Confidence
80% confidence
Finding
Skill enumerates or reads other installed skills. Access to other skills' SKILL.md files or the skills directory reveals prompt instructions, capabilities, and secrets that should be invisible to peer skills.

Skill Enumeration

Medium
Category
Agent Snooping
Content
This project includes the SELF-DISCOVER Reasoning Skill.

Read and follow `skills/self-discover-skill/SKILL.md` before responding to user queries.

The skill activates automatically to compose task-specific reasoning structures.
Confidence
80% confidence
Finding
Skill enumerates or reads other installed skills. Access to other skills' SKILL.md files or the skills directory reveals prompt instructions, capabilities, and secrets that should be invisible to peer skills.

Skill Enumeration

Medium
Category
Agent Snooping
Content
This project includes the SELF-DISCOVER Reasoning Skill.

Read and follow `skills/self-discover-skill/SKILL.md` before responding to user queries.

The skill activates automatically to compose task-specific reasoning structures.
Confidence
80% confidence
Finding
Skill enumerates or reads other installed skills. Access to other skills' SKILL.md files or the skills directory reveals prompt instructions, capabilities, and secrets that should be invisible to peer skills.

Vague Triggers

Medium
Confidence
96% confidence
Finding
The statement that the skill 'activates automatically' is overly broad and implies implicit execution without clear user consent, scope limits, or trigger conditions. In an agent skill system, ambiguous auto-activation can cause hidden prompt injection, unreviewed instruction loading, or unintended behavior whenever user queries are processed.

Vague Triggers

Medium
Confidence
95% confidence
Finding
The manual trigger phrases are broad enough to activate the skill during ordinary conversation, such as when a user says 'think carefully' or 'this is important' in a non-technical context. That can cause unintended internal behavior changes, increase token/cost usage, and make the agent follow a more invasive reasoning workflow than the user expected.

Missing User Warnings

Medium
Confidence
97% confidence
Finding
The skill instructs the agent to persist discovered structures to memory without requiring notice, consent, or limits on what may be stored. If task content contains sensitive user data, proprietary code context, or confidential decision logic, that information could be retained across sessions and exposed to later tasks or users depending on platform isolation.

Intent-Code Divergence

Low
Confidence
84% confidence
Finding
The documentation states that discovered reasoning structures should be cached in `memory/discovered-structures.md` and later advertises file-write-based structure memory support, but the explicit repository file tree does not include a `memory/` directory at all. This is a documentation-level contradiction about whether persistent memory storage is part of the skill package.

Missing User Warnings

Low
Confidence
78% confidence
Finding
This markdown file states that discovered reasoning structures are cached in `memory/discovered-structures.md`, which implies persistent file writes. While file-write capability is mentioned elsewhere in compatibility tables, the README does not clearly warn users near this behavior that enabling structure memory may modify project files or persist task-derived content.

Static analysis

No suspicious patterns detected.