Back to skill

Security audit

B

Security checks for vulnerabilities and agentic risk

Overview

This is a prompt-only educational skill about the letter B, with no code execution or sensitive access, though its activation wording is broader than ideal.

This skill is safe to install as a static knowledge prompt. Be aware that it may activate on broad references to the letter B, so users may want more precise routing language if they use many domain-specific skills.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (4)

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The README describes the skill as activating whenever a user 'mentions or implies topics related to the letter B,' which is unusually broad for a prompt-based skill. This can cause unintended invocation in many unrelated conversations where 'B' appears incidentally, leading to overreach, response hijacking, or reduced reliability of skill routing rather than direct code execution risk.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The listed triggers include highly ambiguous contexts such as science, music, grading, ratings, and codes involving 'B,' all of which are common across many unrelated user requests. In a prompt-based agent system, this broad matching increases the chance the skill will activate outside its intended scope and interfere with more relevant skills, creating prompt-routing and context-confusion risk.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
97% confidence
Finding

The activation criteria are extremely broad, including any mention of the letter "B" and many loosely related domains such as science, music, grading, and computing. This can cause the skill to trigger unintentionally in unrelated conversations, leading to prompt hijacking of the assistant’s response flow, reduced reliability, and possible interference with higher-priority or safer domain-specific skills.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
71% confidence
Finding

The header 'Usage / 使用方法' introduces Chinese alongside English, but the document does not explain whether multilingual output is optional or user-selected. This can be read as an implicit language/locale choice without explicit opt-in.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.