Back to skill

Security audit

Ultimate Domain Payload

Security checks for vulnerabilities and agentic risk

Overview

The skill is not overtly malicious, but it automatically installs another skill and covers high-stakes health, financial, legal, and minors-related workflows without enough user-control or safety boundaries.

Install only if you are comfortable with a broad meta-skill that may install and load universal-task-os. Require explicit approval and provenance checks before any dependency install, and treat health, legal, tax, investment, estate, minors, and crisis-related outputs as planning drafts that need qualified human review and careful privacy handling.

Vulnerability Patterns
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (1)

T08 · Insecure Dependencies

Warning
Location
SKILL.md:96
Finding

Automatic Installation and Loading of an Unverified External Skill

Content
View full analysis

Vulnerability Details

File Location: SKILL.md, lines 96-105
Vulnerability Type: Unverified third-party dependency installation and loading
Risk Level: Medium

Vulnerable Code Snippet

markdown
**Loading check process** (performed on every activation):

1. Check whether the `universal-task-os` Skill is installed
2. **Not installed** → automatically install the `universal-task-os` Skill
3. **Installation succeeds** → load UTOS and execute according to this Skill's usage rules
4. **Installation fails** → fall back to **read-only reference mode**:
   - Allowed: consult the domain registry, task catalogs, requirements, and exemplar indexes
   - Denied: cross-domain orchestration, pipeline generation, and content-production tasks

The original source expresses these instructions in Chinese; the snippet above is a faithful English translation.

Technical Analysis

The Skill instructs the agent to automatically install and load the external universal-task-os Skill whenever the dependency is absent. It does not specify:

  • An authoritative registry or repository
  • An immutable version or commit
  • A cryptographic checksum or signature
  • Publisher verification
  • Dependency provenance requirements
  • User approval before installation
  • A least-privilege execution boundary

Because the dependency is not included in the audited project, its implementation and effective privileges could not be assessed. Resolving it solely by name creates exposure to dependency confusion, namespace takeover, typosquatting within a configured Skill source, or compromise of the legitimate upstream package.

The issue is classified as an insecure dependency rather than direct remote-payload execution because the reviewed file does not specify an external URL or concrete retrieval command. Nevertheless, installation necessarily transfers trust to content outside the audited artifact.

Attack Path

  1. An atta ...[truncated 1345 chars]
Remediation
View remediation

Remediation Suggestions

  1. Remove automatic installation from the activation path.
  2. Require explicit, informed user approval before installing any external Skill.
  3. Declare an authoritative registry and publisher identity for universal-task-os.
  4. Pin the dependency to an immutable version or commit rather than resolving the latest package by name.
  5. Verify a cryptographic checksum or trusted publisher signature before installation and loading.
  6. Audit the exact pinned dependency artifact and retain its audit record alongside this Skill.
  7. Reject dependencies whose source, identity, version, or integrity cannot be verified.
  8. Install and run the dependency with the minimum required filesystem, network, execution, and data-access permissions.
  9. Preserve the existing read-only fallback when the dependency is absent or verification fails.
  10. Record dependency installation and verification events in an auditable log without exposing sensitive data.
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
Findings (53)

Missing User Warnings

High
Category
Not specified by scanner
Confidence
97% confidence
Finding

This section provides operational crisis-intervention guidance for a user with suicidal ideation, including triage and handling steps, but does not present an explicit immediate emergency warning directed to the end user to contact local emergency services, a suicide/crisis hotline, or urgent in-person care. In a health workflow skill, omission of that warning can cause dangerous delay, over-reliance on the agent, and inappropriate substitution of templated guidance for urgent professional intervention.

Content

No source excerpt is available for this finding.

Missing User Warnings

High
Category
Not specified by scanner
Confidence
97% confidence
Finding

This section directs collection of children's basic data, family-related service needs, and education-resource information without any child-safety or privacy controls. Because the subject matter involves minors, even seemingly routine data gathering materially raises safeguarding, consent, profiling, and exposure risks.

Content

No source excerpt is available for this finding.

Missing User Warnings

High
Category
Not specified by scanner
Confidence
96% confidence
Finding

The education citizen-journalist workflow encourages interviewing, investigating, and publishing around children-related topics with no warning about minors' consent, image/privacy rights, or safeguarding boundaries. This can facilitate harmful exposure of children, disclosure of sensitive family or school information, and reputational harm from inaccurate reporting.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

The trigger phrases are extremely broad and overlap with generic discussion topics such as life domains, cross-domain orchestration, and human activity classification. This increases the chance of accidental invocation in unrelated conversations, causing the agent to load a highly privileged meta-skill unexpectedly and potentially alter behavior across many domains.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
97% confidence
Finding

The skill instructs the system to automatically detect, install, and load another skill (universal-task-os) during activation, but the description does not warn the user about this side effect. Silent dependency installation expands the execution surface and trust boundary without informed consent, which is especially risky here because this meta-skill is designed to orchestrate actions across many sensitive domains.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The skill explicitly supports outputs such as health plans, reports, and advice in a domain that also includes diagnosis guidance, treatment management, emergency triage, and nutrition guidance, but it does not provide a clear user-facing limitation that the content is informational only and not a substitute for licensed medical judgment. In a health orchestration framework, that omission increases the chance that users or downstream agents treat generated guidance as authoritative medical advice, which can cause delayed care, inappropriate self-treatment, or unsafe decisions in urgent situations.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
97% confidence
Finding

The file presents medical guidance tasks such as symptom analysis, emergency judgment, treatment comparison, and medication management without visible warnings that the output is informational only and not a substitute for licensed medical care. In a high-risk domain like health, omission of escalation and professional-care guidance increases the chance that users or agents act on unsafe advice during urgent or complex situations.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

The catalog exposes concrete medical diagnosis, emergency-triage, treatment-comparison, medication-management, and rehabilitation tasks inside a supposedly orchestration-focused payload. In a health context, these capabilities can be directly operationalized by downstream agents without requiring clinician oversight, creating risk of unsafe medical advice, delayed care, or harmful self-treatment.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

This file provides extensive health assessment, diagnostic guidance, treatment management, and emergency-triage style instructions, but it does not prominently warn that outputs may involve sensitive personal health data or that the material is not a substitute for licensed medical care. In this context, users may over-rely on the skill for self-diagnosis, urgent-care decisions, medication management, or mental-health screening, increasing the risk of harmful delays, unsafe decisions, and inappropriate handling of medical information.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The catalog includes actionable investment selection, tax filing, cross-border tax planning, will/trust planning, and insurance decisions without any caution that these are regulated, jurisdiction-specific, and potentially high-impact activities. In an agent skill context, this can be operationalized into concrete advice or execution steps, increasing the risk that users receive unsafe or non-compliant financial/legal guidance and suffer monetary loss or legal consequences.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The file contains concrete, step-by-step financial, investment, insurance, tax, and inheritance planning actions presented as executable workflows, but it does not provide a clear warning that the material is educational and not personalized professional advice. In a skill designed for orchestration and direct consumption, users may over-rely on these recommendations as authoritative instructions, creating risk of financial loss, unsuitable investments, tax mistakes, or legal errors in estate planning.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

This file systematically instructs collection and organization of highly sensitive personal financial data, including assets, liabilities, income, taxes, insurance, cross-border tax status, wills, trusts, and inheritance planning, but provides no privacy, minimization, retention, or consent safeguards. In an agent skill context, that omission is dangerous because downstream systems may prompt users to disclose comprehensive financial profiles and legal-family information without warning, increasing the risk of oversharing, unsafe storage, or secondary misuse.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The skill content is entirely in Chinese while the broader agent ecosystem or user may operate in another language, and the file provides no explicit language declaration, negotiation, or fallback behavior. This can cause users or downstream agents to misunderstand instructions, calibration requirements, or dependency semantics, creating a prompt-confusion and unsafe-execution risk rather than a memory-safety issue.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
89% confidence
Finding

这是一个 markdown 文件,因此适用 SQP-3。标题及整篇说明均以中文固定呈现,且文中没有说明可根据用户偏好切换语言或仅面向特定中文地区用户,构成未征得用户选择即强制特定语言/locale 的自然语言策略问题。

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

This markdown file presents all instructions and requirements exclusively in Chinese, which can amount to a language-policy violation when users are not given an opt-in or alternative locale. The file does not indicate that it is intended only for a Chinese-language or region-specific context.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
88% confidence
Finding

The manifest and body are written entirely in Chinese, with the domain and description specified only in Chinese and no indication that users may choose another language. This creates a natural-language policy concern because it implicitly fixes the interaction locale without opt-in or a documented region-specific justification.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

The document title and all operating instructions are written entirely in Chinese, and the file does not indicate that language selection is optional or that the skill is intended only for a Chinese-speaking or region-specific context. Under the policy, forcing a specific language without user opt-in is a natural-language locale violation.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

This catalog covers high-stakes topics such as marriage, divorce, pregnancy, childcare, eldercare, finance, and legal decision-making, yet it provides no boundary statements, risk warnings, or referrals to qualified professionals. In a skill intended for broad orchestration across life domains, that omission increases the chance that users or downstream agents treat the checklist as actionable professional guidance in areas where mistakes can cause health, legal, financial, or family harm.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

The file’s instructional content is entirely written in Chinese, and there is no indication that users may choose another language or that the skill is specifically limited to a Chinese-speaking or region-specific context. Under the policy rule for language/locale constraints, this is a natural-language policy issue because it imposes a language assumption without opt-in.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
90% confidence
Finding

The manifest and document description are entirely in Chinese, including the domain label and functional description, with no indication that users may choose another language or that the locale restriction is intentional. This can violate language/locale policy when a skill implicitly enforces one language without offering opt-in or documenting a justified regional scope.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
86% confidence
Finding

This markdown file presents the entire skill catalog only in Chinese, with no indication that other languages are supported or that Chinese is an opt-in locale. Under the policy for natural-language violations, forcing a specific language without user choice can be a locale-policy issue.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

The entire skill file is written as a Chinese-only exemplar set and does not indicate that users may choose another language or locale. Under the stated policy, forcing a specific language without user opt-in is a natural-language policy violation unless the locale restriction is explicitly justified.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

The manifest and content present the skill entirely in Chinese, including the domain and description, with no indication that users may choose another language or that Chinese is required for a specific regional/legal compliance reason. This can violate a language/locale policy when a skill implicitly restricts interaction to one language without opt-in.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

The file defines extensive legal workflows, including contracts, disputes, compliance, privacy, inheritance, and litigation preparation, but provides no warning that outputs may constitute professional legal guidance and may depend heavily on jurisdiction-specific law. In practice, a user or downstream agent could treat these structured outputs as authoritative legal advice, leading to unsafe reliance, privacy-sensitive processing, or legally incorrect actions.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

This markdown skill file uses Chinese for the domain, description, and core usage instructions, and does not indicate that users may choose another language. Under the policy rule for natural-language violations, forcing a specific language without user opt-in is a reportable issue.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.