Back to skill

Security audit

car-seat-stage-pilot

Security checks for vulnerabilities and agentic risk

Overview

The skill is not malicious, but it gives overconfident and internally inconsistent child car-seat transition guidance in a safety-sensitive area.

Review carefully before installing. This skill appears technically simple and non-malicious, but it should not be relied on as a final child-safety decision tool; verify any result against the exact car-seat manual, local law, and a certified child passenger safety technician, especially before turning a child forward-facing or moving to a booster.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
Findings (3)

Missing User Warnings

High
Category
Not specified by scanner
Confidence
95% confidence
Finding

The skill promises a 'definitive stage verdict' based on birthday and optional measurements, despite acknowledging that correct staging also depends on the specific seat's limits and other contextual factors. Presenting certainty in a child-safety decision tool can mislead parents into relying on generalized output where seat-manual constraints, maturity, belt fit, or jurisdictional rules may change the correct answer.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

The trigger language is broad enough to catch many general questions involving child age and car-seat transitions, which can cause the skill to activate in situations where it lacks the necessary seat-specific, vehicle-specific, or legal context. In a safety-critical domain, unintended invocation increases the chance that users receive overconfident guidance from incomplete inputs.

Content

No source excerpt is available for this finding.

Intent-Code Divergence

Medium
Category
Not specified by scanner
Confidence
98% confidence
Finding

The example directly contradicts the skill's own safer guidance by telling a parent that a 30-month-old, 24 lb, 31 in child may be forward-facing solely because the age floor is met. In a child-passenger-safety context, contradictory exemplar output is dangerous because examples strongly shape downstream behavior and could normalize premature transition out of rear-facing, increasing injury risk in a crash.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.