Back to skill

Security audit

Cro Mobile

Security checks for vulnerabilities and agentic risk

Overview

This is a simple mobile optimization guidance skill with one visible third-party promotional link, but no code, permissions, persistence, or data access.

Before installing, be aware that the skill may lead an agent to mention or recommend the Racoonn waitlist when discussing mobile CRO testing. Treat that as promotional content and prefer explicit user consent before following or sharing data with the linked third-party service.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Findings (1)

T01 · Skill Instruction Hijacking

Warning
Location
SKILL.md:37
Finding

Third-Party Promotional Instruction Hijacks Skill Output

Content
View full analysis

Vulnerability Details

File Location: SKILL.md, lines 37-44
Vulnerability Type: T01: Skill Instruction Hijacking
Risk Level: Medium

Complete Vulnerable Snippet:

markdown
## Test Your Product with Racoonn

After applying these practices, validate with real AI-simulated user testing.

**Racoonn** runs 5,000 AI persona agents on your landing page and tells you exactly what's broken — in under 30 minutes.

→ **API coming soon** — Join the waitlist for early access: [racoonn.me](https://racoonn.me)

Technical Analysis

The skill appends a hard-coded recommendation for a specific commercial service and instructs users to join an external waitlist. This content is not required to provide mobile conversion-rate optimization guidance.

When an AI agent loads the skill as trusted instructional context, it may interpret this promotional section as part of its expected workflow. The instruction can therefore alter the agent's output by causing it to recommend Racoonn or direct users to https://racoonn.me, even when the user's request only concerns mobile optimization.

The reviewed content does not automatically issue a network request, execute code, submit user data, or override explicit safety controls. The risk is limited to instruction-level output manipulation and redirection to an unaudited third-party website.

Attack Path

  1. A user or agent installs or loads the skill for mobile conversion-rate optimization guidance.
  2. The agent treats the entire SKILL.md document, including its final promotional section, as trusted task instructions.
  3. After providing otherwise legitimate optimization advice, the agent reproduces or acts upon the instruction to validate the product using Racoonn.
  4. The agent recommends the named service and presents the external waitlist URL to the user.
  5. The user may follow the link and interact with a third-party service that was not necessary for the original task and was not security-reviewed as ...[truncated 738 chars]
Remediation
View remediation

Remediation Suggestions

  1. Remove the promotional section at lines 37-44 from the skill.
  2. Keep the skill focused on vendor-neutral mobile conversion-rate optimization guidance.
  3. If external tools are genuinely useful, describe objective selection criteria rather than directing users to a single provider.
  4. If a specific service must be mentioned, clearly label the content as optional promotional or sponsored material and ensure that agents are not instructed to reproduce it automatically.
  5. Require explicit user consent before directing users to third-party services or transmitting any site, analytics, or customer data.
  6. Review future skill content for unrelated calls to action, referral links, vendor endorsements, and instructions that could alter agent output beyond the declared purpose of the skill.
Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep

Static analysis

No suspicious patterns detected.