Back to skill

Security audit

JavaScript

Security checks for vulnerabilities and agentic risk

Overview

This is a JavaScript style-guide skill with broad automatic activation wording, but it contains no executable code, persistence, credential handling, or hidden high-impact behavior.

Install only if you want JavaScript-related requests to be answered according to this specific style guide; be aware it may apply its conventions whenever JavaScript is mentioned, even when you did not explicitly ask for style enforcement.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (4)

Vague Triggers

High
Category
Not specified by scanner
Confidence
97% confidence
Finding

The skill activates whenever a user 'mentions or implies JavaScript', which is an unusually broad trigger for a prompt-based skill. This can cause unintended activation in unrelated conversations, leading the agent to inject style-guide behavior or code-generation instructions where they were not explicitly requested, increasing prompt-scope confusion and the chance of interfering with higher-priority task handling.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

The README states the skill 'automatically activates when you mention or imply JavaScript in conversation,' which is an overly broad natural-language trigger. This can cause unintended activation during ordinary discussion, making the assistant apply this skill in contexts where the user did not explicitly request it and increasing the risk of prompt-scope hijacking or inappropriate behavior shaping.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

Describing the skill as a 'Natural Language — Prompt-based Skill' with 'No special commands or syntax required' lacks clear trigger constraints and boundaries. In practice, this makes activation ambiguous and increases the chance the skill will engage on loosely related text, overriding user intent or interfering with other skills and base safety behavior.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The 'Simply mention JavaScript' automatic activation instruction reinforces a broad keyword trigger with no contextual constraints. In practice, this can make the skill fire on casual references, causing unnecessary prompt injection into the assistant's behavior and reducing predictability, though the content here is a style guide rather than directly privileged or destructive logic.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.