Back to skill

Security audit

tester-skill-vito

Security checks for vulnerabilities and agentic risk

Overview

This skill is a disclosed Firecrawl workflow router that asks an agent to gather web evidence and produce user-requested deliverables; the main caution is to keep scraping scope explicit.

Before installing, be aware that this skill uses Firecrawl and a required API key to collect web evidence for deliverables. Give it explicit targets and limits, especially for auth-gated content, lead lists, competitor monitoring, or large research jobs, and review any sources or rerun inputs it produces.

Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (2)

Vague Triggers

Medium
Confidence
86% confidence
Finding
The activation description is broad enough to match many generic business, marketing, product, or creative requests, which can cause this skill to be invoked when a narrower or safer specialized workflow would be more appropriate. Over-broad routing increases the chance of unintended web access, unnecessary data collection, and user confusion about what actions the agent will take.

Vague Triggers

Medium
Confidence
82% confidence
Finding
Telling the agent to infer workflow, inputs, audience, and output format from surrounding context encourages ambiguous activation and assumption-making without explicit user confirmation. In security-sensitive or high-cost scraping contexts, this can lead to collecting data from the wrong targets, performing broader reconnaissance than intended, or producing deliverables based on guessed requirements.

Static analysis

No suspicious patterns detected.