Back to skill

Security audit

Sa Pro Workbench International

Security checks for vulnerabilities and agentic risk

Overview

This appears to be a presales/document-template skill with some overbroad trigger wording and legal-template caveats, but no evidence of malicious behavior.

Safe to install for drafting presales and project documents. Review generated SOW/legal language with qualified counsel before reuse, and invoke the skill intentionally when working with confidential business content.

Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (2)

Vague Triggers

Medium
Confidence
89% confidence
Finding
The trigger guidance is extremely broad ('Just describe your need') and includes common enterprise tasks like drawing diagrams, writing designs, and responding to RFPs. In a skill system, this can cause unintended invocation across many normal conversations, which may route sensitive business content into the skill without deliberate user intent.

Natural-Language Policy Violations

Medium
Confidence
91% confidence
Finding
The SOW template hard-codes a dispute venue as an 'arbitration commission / competent people's court' without clearly framing this as a selectable placeholder tied to jurisdiction-specific legal review. In an international presales/workbench context, users may reuse the template as-is, creating unenforceable, biased, or inappropriate dispute-resolution clauses for the wrong country or legal system.

Static analysis

No suspicious patterns detected.