Back to skill

Security audit

Smart Procurement Navigator International

Security checks for vulnerabilities and agentic risk

Overview

This is a disclosed procurement-document assistant with expected handling of tender files and bid materials, with no executable payloads or hidden data-transfer behavior found.

Install only in a workspace approved for procurement materials. Before uploading real tenders, proposals, qualifications, prices, or historical bid responses, confirm you are authorized to process them there and redact unnecessary confidential or regulated data.

Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (7)

Vague Triggers

Medium
Confidence
84% confidence
Finding
The trigger guidance invites activation from very broad, natural-language prompts such as 'just describe your need' without defining procurement-only boundaries or excluding unrelated sensitive tasks. In agent environments, overly broad invocation language can cause the skill to activate in unintended contexts and steer the model into handling documents or decisions beyond its intended scope.

Vague Triggers

Medium
Confidence
88% confidence
Finding
The trigger phrase is broad enough that it could be invoked in routine conversation, increasing the chance of accidental activation outside the intended demo context. In a procurement workflow, unintended activation may cause the assistant to begin processing sensitive business or procurement materials without clear user intent or appropriate review.

Missing User Warnings

Medium
Confidence
95% confidence
Finding
The script instructs users to upload procurement documents and technical specifications but provides no warning about confidentiality, regulated data, or privacy risks. Procurement materials commonly contain non-public pricing, technical details, vendor information, or government-related content, so encouraging uploads without safeguards can lead to inappropriate disclosure or policy violations.

Natural-Language Policy Violations

Medium
Confidence
85% confidence
Finding
The prompt states that international tenders typically use English, which can cause the skill to default outputs to English without confirming the user's preferred language. In procurement workflows, an unexpected language switch can cause misunderstanding, review delays, or submission-preparation errors, especially where bilingual compliance review is required.

Vague Triggers

Medium
Confidence
92% confidence
Finding
The example invocation uses a broad natural-language trigger addressed to '@ProcurementAdvisor' without any visible scoping, permission boundary, or activation constraint. In a collaboration platform, such generic phrasing can cause accidental or undesired invocation on unrelated procurement documents or conversations, potentially leading to unintended processing of sensitive attachments or task execution.

Vague Triggers

Medium
Confidence
89% confidence
Finding
This task-breakdown example relies on context from 'the procurement document just reviewed' but does not define how context is bound to a specific prior document or session. That ambiguity can let the agent act on stale, wrong, or cross-thread data, creating a risk of information leakage, incorrect work product, or unintended activation in normal conversation.

Vague Triggers

Medium
Confidence
91% confidence
Finding
The review request is phrased broadly and could match ordinary collaboration messages requesting document review, making unintended activation more likely. Because the requested actions involve scanning drafts for residual references and compliance issues, accidental execution could expose confidential bid content or produce unauthorized analysis in the wrong context.

Static analysis

No suspicious patterns detected.