Back to skill

Security audit

covercraft-skill

Security checks for vulnerabilities and agentic risk

Overview

This skill is a coherent cover and thumbnail design workflow with optional local helper scripts, and its file access is limited to user-directed inputs and outputs.

Installers should expect this skill to ask for titles, platform details, reference covers, portraits, and optional files when doing batch briefs or image QC. Use it when you want a structured cover workflow; review portrait/reference-image use carefully because it gives detailed likeness and style-direction prompts, though the skill also tells the agent not to identify real people or copy protected designs.

Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (2)

Vague Triggers

Medium
Confidence
91% confidence
Finding
The skill is framed broadly enough to trigger on many generic design or image-help requests, increasing the chance it overrides a more appropriate specialist skill or activates when the user did not intend to use it. Overbroad activation can become a security issue when a skill steers conversations into workflows involving files, images, or external scripts without sufficiently narrow gating.

Vague Triggers

Medium
Confidence
89% confidence
Finding
The invocation examples use broad everyday phrases such as helping make or optimize covers, which can match routine user requests with little constraint. This increases unintended activation risk and could expose users to unnecessary data collection prompts, image-processing flows, or file-based tooling when a simpler response would suffice.

Static analysis

No suspicious patterns detected.