Back to skill

Security audit

company-tech-profile

Security checks for vulnerabilities and agentic risk

Overview

This skill is a disclosed research workflow for creating company technology reports, with file creation and web/patent/paper research that fit its purpose.

Before installing, expect this skill to perform external research and create local report/evidence files. For best control, give an explicit company, technology topic, purpose, and time window; if you provide only a company name, review the inferred topic before relying on the output.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Vulnerability Patterns
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
Findings (2)

External Model or Provider Selection

Medium
Category
Excessive Agency
Confidence
90% confidence
Finding

Skill selects an external model or provider that may use a different account or billing plan than the operator expects. Undisclosed model switches can cause unexpected cost or quota consumption.

Content

Scanner excerpt · SKILL.md (reported line 12)May include surrounding context.

md
only mention a company plus a technology area without explicitly asking for a
  "profile".
argument-hint: "[company + topic + optional purpose/time window]"
provider: "Patsnap Eureka"
compatibility: "Designed for Claude Code, Codex, and similar agent runtimes that can read/write local files and call whatever search tools are available."
deliverable-default: "Structured Markdown report plus traceable evidence files; docx/pdf export is optional."
fallback-policy: "Prefer structured patent/paper retrieval when available; otherwise downgrade through domain-specific sources, Exa, Tavily, Brave, web, and a known-URL reader without blocking the run."

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

The skill explicitly says to proceed even when the user provides only a company name and no topic, inferring a technology area from context rather than requiring clear user intent. That broad invocation/routing can cause the agent to launch external research, create files, and generate a substantive profile on an underspecified request, increasing the risk of over-collection, mistaken scope, or analysis of a company/topic the user did not actually request.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.