Back to skill

Security audit

Goal Mode

Security checks for vulnerabilities and agentic risk

Overview

This browsing skill is purpose-built but needs Review because it automatically keeps durable records of broad browsing activity and has under-scoped workspace write paths.

Install only if you are comfortable with this skill saving your goals, constraints, visited-page metadata, extracted findings, recommendations, and history into workspace files. Avoid using it for sensitive health, legal, financial, employment, or private research unless the publisher adds clear retention controls, a no-save mode, goal_slug validation, and stronger handling of untrusted webpage text.

Vulnerability Patterns
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (2)

T05 · Unauthorized Access and Privilege Escalation

Error
Location
references/evaluate-page.md:102
Finding

Unvalidated goal_slug Allows Workspace Path Traversal

Content
View full analysis
Remediation
View remediation

T02 · Agent Memory Poisoning

Warning
Location
references/evaluate-page.md:109
Finding

Untrusted Web Content Is Propagated into Persistent Agent Memory

Content
View full analysis
Remediation
View remediation
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Findings (10)

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The skill explicitly states that it persists all session data to the workspace, but it provides no user-facing notice, consent mechanism, or data-minimization boundary. Because this skill supports broad goal types including health, career, and decision-making, it may store sensitive browsing goals, page evaluations, and summaries without the user realizing durable local records are being created.

Content

No source excerpt is available for this finding.

Ssd 3

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

Persisting all session data creates a retention risk because the stored material can include raw goals, criteria, page findings, and possibly sensitive inferences in natural language. In a multi-domain browsing assistant, those records may reveal private interests or circumstances long after the session ends, increasing exposure if the workspace is accessed by other tools, users, or processes.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
97% confidence
Finding

The workflow mandates writes before every response, making storage automatic and unavoidable for all operations. This is dangerous because even simple evaluation requests will silently create persistent artifacts, increasing the chance that sensitive user intent, browsing context, or derived conclusions are retained without informed consent.

Content

No source excerpt is available for this finding.

Ssd 3

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

Requiring reads and writes of all persistence artifacts before responding operationalizes comprehensive retention as part of normal execution. This makes over-collection likely, because every interaction is funneled into durable state and logs whether or not persistence is needed for the user's immediate task.

Content

No source excerpt is available for this finding.

Ssd 3

Medium
Category
Not specified by scanner
Confidence
98% confidence
Finding

The defined file layout includes append-only history, live status, latest-session summaries, full session state, and immutable event logs, which together create broad, accumulating records of user activity. This is especially risky in the stated context because goals may involve health, career, travel, or other personal topics, so the storage design amplifies privacy exposure beyond what is necessary for basic operation.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The skill explicitly requires persistent writes to multiple workspace and memory files, including session history and active-goal state, without any indication of user consent, approval gating, or notice that data will be stored long-term. In a browsing assistant context, this can silently retain potentially sensitive goal text, constraints, findings, and recommendations, creating privacy, integrity, and auditability risks if the user did not intend persistent storage.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The skill explicitly requires persistent storage of every page evaluation, including low-relevance pages, full browsing history, and session state, without any mention of user consent, minimization, or retention limits. This can silently accumulate sensitive research activity, visited URLs, and extracted page-derived data in predictable workspace files, creating a privacy and data-governance risk.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

The skill explicitly requires writing multiple files into the workspace, including an active session pointer and session state, without any mention of user notification, consent, or conditional gating. Persisting data by default can create unintended state changes, leak sensitive goal/constraint data into durable storage, and make later agent behavior depend on hidden prior context.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

The skill instructs persistent writes that change global session state (active-goal.json) and regenerate a memory file as part of a resume operation, but it provides no user warning, confirmation, or safety constraints around mutating workspace state. In a browsing assistant that persists cross-session context, this can unexpectedly overwrite the active goal pointer or session memory, causing state confusion, loss of prior context, or unintended continuation under the wrong goal.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

The operation explicitly performs persistent writes to workspace files and notes that removed criteria lose coverage data permanently, but it does not require an explicit confirmation or user-facing warning before destructive changes are applied. In the context of a goal-tracking skill that persists session state, this creates a real risk of unintended data loss or silent state tampering if an agent invokes the operation based on ambiguous or adversarial input.

Content

No source excerpt is available for this finding.