Back to skill

Security audit

TESP Audit

Security checks for vulnerabilities and agentic risk

Overview

This is a small documentation-only audit skill whose behavior matches its stated TESP governance purpose.

Review the trigger wording if you want this skill invoked only for explicit TESP requests. From the inspected artifacts, it does not install code, run commands, access credentials, or persist changes beyond a disclosed short audit report.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (2)

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
89% confidence
Finding

The trigger text is unusually broad for a governance-oriented skill and overlaps with generic audit, rollout verification, and monitoring requests. In an agentic system, this can cause over-invocation or misrouting, letting the skill activate outside its intended narrow scope and potentially influence unrelated reviews or decision flows.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
83% confidence
Finding

The file includes a Chinese introduction alongside the English description, but it does not state whether language selection is user-driven or optional. Under the policy, locale or language behavior should not be imposed without user choice unless clearly justified.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.