Back to skill

Security audit

Skill Quality Check

Security checks for vulnerabilities and agentic risk

Overview

This is a markdown-only skill-quality checklist that reads skill files and produces audit scores, with no hidden execution, persistence, credential use, or destructive behavior found.

Install only if you want an agent to review other skill files for quality. When using it, point it at a specific local SKILL.md or known GitHub source, and remember that its output is a quality score rather than a security guarantee.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Vulnerability Patterns
  • Rogue AgentSelf-Modification, Session Persistence
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
Findings (11)

Self-Modification

High
Category
Rogue Agent
Confidence
85% confidence
Finding

Skill modifies its own code, configuration, or behavior at runtime. Self-modification enables an agent to escalate privileges, disable safety constraints, or install persistent backdoors.

Content

Scanner excerpt · README.md (reported line 200)May include surrounding context.

md
|------|---------|-------------|
| **Skill Quality Check** | Quality assessment | Evaluating Skills |
| **Skill Vetter** | Security review | Checking for malicious code |
| **Skill Creator** | How to write Skills | Building new Skills |

**Recommended workflow:** Vetter → Quality Check → Creator

Vague Triggers

High
Category
Not specified by scanner
Confidence
98% confidence
Finding

The activation rule says to trigger when the user merely mentions "PDF" or "document," which are extremely common terms in normal conversation. This can cause the skill to activate unintentionally, injecting irrelevant instructions into unrelated tasks and potentially overriding or polluting the assistant's behavior whenever commonplace document-related language appears.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

The description says to use the skill "before installing or after writing any SKILL.md" and includes generic keywords like "audit, quality, review, score, assess, best practices, vet." In a markdown skill file, these broad terms overlap with common evaluation requests and do not provide clear exclusion conditions, increasing mis-trigger risk.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
99% confidence
Finding

The scoring table includes Chinese text ("有明显缺陷") in an otherwise English document, and a later example also includes Chinese wording ("明确的职责范围"). This imposes a language inconsistency without user opt-in or a documented reason, which is a natural-language locale policy issue.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
99% confidence
Finding

The phrase "明确的职责范围" appears in an English-language example without any user language preference or explanation. This creates an undocumented language constraint/inconsistency that may not align with organizational language policy expectations.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
89% confidence
Finding

The example trigger phrase "Help me with a PDF" is broad and closely matches ordinary user requests, reinforcing an activation pattern that can collide with normal conversation. While this example alone is less dangerous than an explicit auto-activation rule, it encourages ambiguous triggering behavior and increases the chance of accidental skill invocation.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
88% confidence
Finding

The manifest description contains broad keywords such as "document" and potentially generic action terms that may match many non-PDF tasks. In skill-selection systems that rely on description keywords, this can cause over-triggering and misrouting, leading the agent to apply PDF workflows where they are not appropriate.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The invocation guidance includes generic terms like "document" and "rotate," which can cause the skill to activate for unrelated user requests. That increases the chance of incorrect tool selection or unintended file-handling behavior, especially in agents that auto-route based on keyword overlap.

Content

No source excerpt is available for this finding.

Intent-Code Divergence

Low
Category
Not specified by scanner
Confidence
95% confidence
Finding

The README documents this skill as "Skill Quality Check" / "skill-quality-check", but the usage example says "Use skill-audit" and the file structure is rooted at "skill-audit/". This contradicts the documented identity and invocation of the skill, creating an intent/documentation mismatch even though no executable code is shown.

Content

No source excerpt is available for this finding.

Vague Triggers

Low
Category
Not specified by scanner
Confidence
92% confidence
Finding

This markdown file includes guidance that treats "debug" as a good trigger keyword on its own. In a skill description or manifest, a standalone trigger this broad could cause unintended invocation because it lacks domain, scope, or exclusion conditions.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
93% confidence
Finding

The document is written in English, but line L206 uses the Chinese term "数量" in the table header/entry. This creates an unexplained language switch and could violate language/locale consistency expectations because no user choice or region-specific justification is provided.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.