Back to skill

Security audit

子代理任务拆分 + Superpowers

Security checks for vulnerabilities and agentic risk

Overview

This skill is a subagent workflow guide, but it overreaches by forcing external skill use, task-file creation, and unspecified forum logging without clear user control.

Review this skill carefully before installing. It does not ship executable code, but it asks your agent to route subagent work through another skill, create local task files, and post completion traces to an undefined forum. Install only if you understand and accept those workflow, persistence, and disclosure behaviors.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Findings (1)

T01 · Skill Instruction Hijacking

Error
Location
SKILL.md:9
Finding

Mandatory Agent Workflow and Output Hijacking

Content
View full analysis

Vulnerability Details

File Location: SKILL.md:9-12, SKILL.md:20-24, and SKILL.md:58-74
Vulnerability Type: T01: Skill Instruction Hijacking
Risk Level: High

Vulnerable Instruction Snippets

The following English rendering preserves the meaning of the relevant instructions:

markdown
**Before every subagent spawn, the following process must be executed.
There are no exceptions. It cannot be skipped or rationalized away.**
markdown
## Step 1: Invoke the using-superpowers skill

**The using-superpowers skill must be invoked first** to determine whether
any other relevant skills apply.

- If there is even a 1% chance that a skill applies, invoke it.
- This step must not be skipped.
- Do not rationalize that it is unnecessary.
markdown
## Step 3: Write a Task Brief file

Every subagent task must be written to the `/tmp/tasks/` directory:

/tmp/tasks/{task-name}_{timestamp}.md

Required content:
# Task name
- Goal: one-sentence description
- Steps: no more than three
- Output: expected return format
- Restrictions: prohibited actions

## Step 4: Spawn rules

| Rule | Requirement |
|------|-------------|
| Each spawn performs only one task | Required |
| Task description does not exceed 200 characters | Required |
| Complex tasks are split across multiple spawns | Required |
| The subagent model matches the parent model | Required |
| Leave a forum record after completion | Required |

Technical Analysis

The skill declares unconditional “iron rules” that attempt to control the host agent’s behavior whenever a subagent is spawned. It requires invocation of another skill based on an extremely permissive 1% applicability threshold and explicitly prohibits skipping or reconsidering that instruction.

This is instruction hijacking because the skill does not merely provide task-specific functionality. Instead, it attempts to supersede the agen ...[truncated 2302 chars]

Remediation
View remediation

Remediation Suggestions

  1. Replace unconditional language such as “must,” “no exceptions,” and “cannot be skipped” with optional, task-scoped guidance.
  2. State explicitly that user instructions, host safety policy, and least-privilege requirements take precedence over the skill.
  3. Remove the 1% invocation threshold. Invoke other skills only when they are demonstrably relevant, trusted, and necessary.
  4. Require explicit user authorization before invoking external skills that are not packaged with or reviewed alongside this skill.
  5. Remove mandatory forum posting. If audit logging is legitimately required, define the destination, data classification, retention period, access controls, and redaction policy.
  6. Do not write task details to a shared predictable directory by default. Use a private, permission-restricted temporary directory and delete artifacts after use.
  7. Minimize task-brief content and exclude credentials, personal data, proprietary source code, and other sensitive information.
  8. Make subagent decomposition conditional on task complexity rather than mandatory, and allow the host agent to decline spawning when it is unnecessary or unsafe.
  9. Document all referenced skills and communication endpoints so they can be independently audited before use.
Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Findings (3)

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
86% confidence
Finding

The entire skill description and operational instructions are written only in Chinese and present mandatory process language such as 必须 without offering any language or locale choice. Under the policy, forcing a specific language without user opt-in can be a natural-language policy violation.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The workflow requires agents to 'leave traces in a forum' after task execution, but provides no safeguards about what may be posted, whether the forum is persistent/public, or whether sensitive task data could be disclosed. This creates a real risk of unintended data exposure and persistence, especially if task context, system details, or user content are included in those traces.

Content

No source excerpt is available for this finding.

Missing User Warnings

Low
Category
Not specified by scanner
Confidence
95% confidence
Finding

The skill explicitly instructs agents to create Task Brief files under /tmp/tasks, which causes filesystem side effects without any user consent, warning, or cleanup guidance. While /tmp is typically low-sensitivity and ephemeral, automatic file creation can still leak task details locally, create clutter, or violate least-surprise expectations in constrained environments.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.