Back to skill

Security audit

Expert Workflow-Composer

Security checks for vulnerabilities and agentic risk

Overview

This is a disclosed workflow-composition skill that inventories available experts and helps coordinate them, with no evidence of hidden execution, credential use, persistence, or exfiltration.

Before installing, be comfortable with the skill listing available marketplace and locally installed experts/teams and using that inventory to suggest or coordinate workflows. Review any custom files you add under references/, keep sensitive business data out of reusable templates, and require explicit confirmation before allowing any write, publish, delete, connector, or expert-dispatch action.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (8)

Intent-Code Divergence

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The skill declares its own contents must not be modified, but then explicitly allows users to add and register files under references/. This creates a policy contradiction that can be abused to smuggle untrusted prompt content into later executions, especially because the skill instructs the agent to load references/ files into context and use them as authoritative guidance.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The skill mandates bilingual user-facing output as a fixed policy rather than adapting to the user's stated language or preference. This can cause unnecessary disclosure, confusion, or prompt-surface expansion in downstream workflows, especially when concise or single-language responses are expected.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
97% confidence
Finding

The validation rule hard-requires bilingual copy without offering a language choice, which overrides user intent and can degrade safety and usability in multilingual settings. In agent workflows, rigid output policies can also interfere with downstream tools or specialists that expect one language only.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
88% confidence
Finding

All user-facing headings, inputs, outputs, and guidance in this template are presented exclusively in Chinese, and there is no indication that users may choose another language or locale. Under the policy, forcing a specific language without user opt-in is a natural-language policy concern.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The requirement that all user-facing copy be bilingual Chinese-English is a hard-coded output policy that overrides user preference and can cause unnecessary disclosure or confusion, especially when prompts or generated content may include sensitive business context that the user only intended to express in one language. In this skill, the risk is primarily policy and UX-related rather than direct code-execution risk, but it is still a real issue because the instruction is mandatory and repeated across the workflow.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
82% confidence
Finding

This markdown skill reference is entirely presented in Chinese and does not provide an opt-in, alternate language, or note that the skill is intended only for Chinese-speaking users. Under the policy, forcing a specific language without user choice can be a natural-language policy violation.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
82% confidence
Finding

Line L134 requires output language to be consistent with the user's original request. While narrower than a fixed-language mandate, it still enforces a locale policy without explicitly allowing the user to request another language or bilingual output.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
77% confidence
Finding

The natural-language instruction includes '输出语言与用户一致' as a fixed rule. Under the policy, language constraints can be a violation when they are enforced without explicit user choice or documented justification.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.