Back to skill

Security audit

It Consulting Workbench International

Security checks for vulnerabilities and agentic risk

Overview

This is not malware, but it is a broad enterprise consulting skill that can steer users into handling sensitive company, employee, cloud, and credential information without enough guardrails.

Install only if you will use it with explicit workflow selection and enterprise data-handling rules. Avoid unnecessary personal profiling, use anonymized or aggregated employee data where possible, require written authorization for repository/log/billing/security access, keep secrets in an approved vault, rotate credentials after handover, and require human approval plus rollback plans for cloud shutdowns, purchases, remediation, and access revocation.

Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
Findings (12)

Vague Triggers

Medium
Confidence
93% confidence
Finding
The trigger guidance is extremely broad ('Just describe your need') and lists many generic example requests, which increases the chance the skill will be invoked unintentionally for loosely related prompts. In an agent environment, overbroad invocation can route sensitive business, architecture, vendor, or security-analysis tasks into this skill when the user did not explicitly intend to use it, creating scope confusion and increasing the chance of inappropriate prompt capture or misuse.

Vague Triggers

Medium
Confidence
95% confidence
Finding
The router includes very broad trigger phrases such as generic requests to 'set up a meeting,' 'help analyze root causes,' 'help with PMO,' and 'need to present to the board.' In an agent ecosystem, these overlaps can cause unintended invocation of this powerful skill in ordinary conversations, leading to context capture, overreach into domains the user did not explicitly select, and accidental disclosure or generation of high-stakes consulting outputs.

Missing User Warnings

Low
Confidence
83% confidence
Finding
The instruction to perform 'LinkedIn / background check' on meeting attendees encourages collection of personal information without any guidance on lawful sources, necessity, consent, or data-minimization. In a business-development context this can lead users to gather excessive or inappropriate personal data, creating privacy, compliance, and reputational risk even if the intent is routine client preparation.

Missing User Warnings

Medium
Confidence
95% confidence
Finding
The skill explicitly instructs collection of interviewees' social media activity, career history, and interpersonal friction, which are sensitive personal and reputational data points. In an enterprise consulting context, gathering and recording such information without consent, minimization rules, or jurisdiction-specific privacy safeguards creates real privacy, ethics, and misuse risks.

Missing User Warnings

Medium
Confidence
97% confidence
Finding
Telling interviewees to expect anonymity without defining limits, storage rules, access controls, or exceptions can mislead participants and encourage disclosure of sensitive information under false assumptions. In practice, this can expose confidential HR, political, or security-relevant details and create legal and trust issues if identities can be inferred or records are shared.

Natural-Language Policy Violations

Medium
Confidence
90% confidence
Finding
The workflow hard-codes a China-specific regulatory and policy framing ('Digital China', Xinchuang, SASAC, data factor policy) as a default step in IT strategy planning without indicating that this applies only to China-based or China-regulated clients. In a general-purpose international consulting skill, this can bias recommendations, produce inapplicable compliance advice, and mislead users into making planning decisions based on the wrong jurisdictional assumptions.

Missing User Warnings

Medium
Confidence
93% confidence
Finding
The document recommends automated shutdown, auto-purchasing, anomaly remediation, and auto-reclaim actions without explicit guardrails, approval steps, rollback guidance, or warnings about production impact. In an enterprise operations context, these automations can cause service disruption, accidental deletion, or financially harmful commitments if applied to the wrong scope or based on noisy detection.

Missing User Warnings

Medium
Confidence
88% confidence
Finding
The tagging policy instructs storing a responsible person's email or employee ID directly in resource metadata without addressing privacy, minimization, or access controls. In many cloud environments, tags are widely visible across billing, inventory, logs, and third-party tools, which can unnecessarily expose personal data and create compliance or internal privacy risks.

Missing User Warnings

Medium
Confidence
86% confidence
Finding
The workflow explicitly recommends tracking each user's usage frequency, identifying non-users and misusers, and conducting 1-on-1 coaching, but it does not include any guardrails around privacy, notice, proportionality, access control, or labor-law/HR review. In an enterprise change-management context, this can normalize employee surveillance practices and lead teams to collect identifiable behavioral data without transparency or lawful basis, creating privacy, trust, and compliance risk.

Missing User Warnings

Medium
Confidence
84% confidence
Finding
The handover checklist explicitly includes transferring accounts, permissions, keys, certificates, and API keys, but it does not instruct users to use a secure secret-transfer method, minimize credential sharing, rotate secrets after transfer, or verify least-privilege access. In an enterprise consulting workflow, this omission can lead to insecure handling of highly sensitive credentials and persistent exposure during project transition.

Missing User Warnings

Medium
Confidence
77% confidence
Finding
The workflow instructs revocation of vendor accounts and permissions at contract closure without warning that access removal must be planned, validated, and sequenced to avoid outages, lockouts, or loss of support during warranty or transition periods. If followed naively, teams could revoke access prematurely or incompletely, creating either operational disruption or lingering unauthorized access.

Natural-Language Policy Violations

Medium
Confidence
90% confidence
Finding
The workflow prescribes a specific outreach channel ('WeChat message or email') and a locale-specific engagement pattern without indicating that the client has opted into those communication methods. In an automated skill, this can lead to privacy, compliance, or professionalism issues if the tool initiates contact over an unauthorized or inappropriate channel for the client’s jurisdiction or preferences.

Static analysis

No suspicious patterns detected.