Back to skill

Security audit

Council Of Llms

Security checks for vulnerabilities and agentic risk

Overview

This is a coherent multi-model review skill, but it under-discloses that copied context may go to cloud models and that it writes a local output file.

Review the configured models before use, especially any cloud-backed ones. Do not paste secrets, credentials, customer data, regulated information, or proprietary material unless you are comfortable sending it to those model providers. Expect a council-review markdown file to be created, and review or pin the companion subagent skill before installing.

Vulnerability Patterns
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
Findings (2)

T09 · Insecure Skill Coding Practices

Warning
Location
SKILL.md:46
Finding

Cloud Model Context Disclosure Is Hidden by Inaccurate Safety Claims

Content
View full analysis
Remediation
View remediation

T08 · Insecure Dependencies

Warning
Location
README.md:58
Finding

Third-Party Skills Are Installed from Mutable Unpinned Sources

Content
View full analysis
Remediation
View remediation
Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
Findings (3)

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The trigger list includes very broad terms such as 'review', 'analysis', and 'decision', which are common in normal conversations and can cause unintended activation. In an orchestration skill that spawns three parallel subagents, accidental triggering can lead to unnecessary model invocations, cost, noise, and unintended propagation of sensitive context into subagent prompts.

Content

No source excerpt is available for this finding.

Intent-Code Divergence

Medium
Category
Not specified by scanner
Confidence
98% confidence
Finding

The skill’s security section materially understates capability by claiming there are no file writes, while earlier instructions explicitly direct writing a synthesis markdown file to the workspace. This kind of incorrect safety claim can mislead operators into granting trust or running the skill without realizing it modifies local files, weakening informed consent and review.

Content

No source excerpt is available for this finding.

Missing User Warnings

Low
Category
Not specified by scanner
Confidence
91% confidence
Finding

The skill instructs writing a synthesis file to the workspace but does not prominently warn the user that local files will be created or modified. Even though the write is limited to markdown output, silent or poorly disclosed workspace modification can surprise users, overwrite files with similar names, or create audit and data-handling issues.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.