Back to skill

Security audit

Prompt Engineering

Security checks for vulnerabilities and agentic risk

Overview

This is a documentation-only prompt-engineering skill with one cautionary refusal-reframing example, but no hidden execution, persistence, credential handling, or data exfiltration behavior.

Reasonable to install if you want prompt-engineering templates and troubleshooting guidance. Review the refusal-related troubleshooting example critically, avoid using it to bypass safety rules, and adapt platform-specific examples such as file paths to your environment.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Findings (4)

Anti-Refusal Statement

High
Category
Anti-Refusal
Confidence
80% confidence
Finding

Skill instructs the agent to omit warnings, disclaimers, or ethical commentary. Stripping safety caveats hides risk from the user and is a common jailbreak preamble.

Content

Scanner excerpt · examples/EXAMPLES.md (reported line 51)May include surrounding context.

md
- Explain methodology before results

### Don'ts
- Don't make predictions beyond 12 months without caveats
- Don't ignore outliers without investigation
- Don't present correlation as causation
- Don't use jargon without explanation

Ssd 1

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The troubleshooting guidance recommends reframing a harmful request with fictional or novel-writing context to get past a model refusal. Even though presented as a prompt-engineering tip, this normalizes jailbreak-style refusal circumvention and can help users obtain assistance for unsafe topics under a benign pretext.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
82% confidence
Finding

The file includes natural-language instructions that require analysis to always follow an English output structure such as 'Executive Summary', 'Key Findings', and 'Recommendations'. This imposes a language/locale expectation without any opt-in, alternative locale support, or justification that the skill is region-specific.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
85% confidence
Finding

The guidance explicitly marks Windows-style paths as incorrect and recommends only Unix-style alternatives. This imposes a platform-specific convention in natural language without offering user opt-in or documenting a justified scope limitation, which can violate locale/environment flexibility expectations.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.