Back to skill

Security audit

Customer Record Field Prep

Security checks across malware telemetry and agentic risk

Overview

This skill only reformats user-supplied customer record notes into a structured field and does not ask for files, credentials, network access, persistence, or elevated authority.

Before installing, confirm that this skill is only used when you want supplied `record_note` data converted into a structured `record_field`; avoid using it for broader customer support analysis or unrelated reporting tasks unless the instructions are tightened.

Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (1)

Vague Triggers

Medium
Confidence
90% confidence
Finding
The activation text is broad enough that the skill could be invoked for loosely related 'routine customer reporting work' without strong trigger boundaries. In an agent environment, vague activation criteria can cause the wrong skill to process user-controlled content, leading to data mishandling, incorrect transformations, or unintended chaining with other skills.

VirusTotal

63/63 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.