Back to skill

Security audit

test

Security checks for vulnerabilities and agentic risk

Overview

This civil-engineering skill does not run code, but it presents high-stakes engineering outputs as if they can be reviewed, approved, or certified without clear licensed-professional limits.

Review this skill carefully before installing. It should be treated as a drafting and analysis aid only; do not rely on it for construction, permit submission, shop drawing approval, site acceptance, or completion certification unless all outputs are independently checked and signed off by a properly licensed engineer in the project jurisdiction. Avoid storing sensitive project details unless you are comfortable with the platform's memory behavior.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Memory PoisoningPersistent Context Injection, Context Window Stuffing, Memory Manipulation
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
Findings (4)

Missing User Warnings

High
Confidence
97% confidence
Finding
This skill instructs the agent to produce structural designs, calculation packages, construction documentation, code compliance matrices, shop drawing reviews, site-inspection outputs, and even completion certificates without any explicit limitation that outputs are preliminary and must be reviewed, sealed, and approved by licensed professionals. In a high-stakes civil/structural context, users could over-rely on unsafe or jurisdictionally noncompliant output, leading to design errors, construction defects, regulatory violations, or life-safety failures.

Memory Manipulation

High
Category
Memory Poisoning
Content
### Geotechnical Rigor

- Never assume soil parameters without a ground investigation report or clear stated assumptions
- Settlement analysis is mandatory for structures sensitive to differential settlement
- Temporary works (excavations, shoring) require the same code rigor as permanent works
Confidence
80% confidence
Finding
Skill manipulates agent memory, state, or stored context. Memory corruption can alter personality, override safety rules, or cause unpredictable behavior.

Ae4

Medium
Category
analysis-evasion
Confidence
80% confidence
Finding
Suspicious Unicode normalization or mixed-script content

Vague Triggers

Medium
Confidence
95% confidence
Finding
The activation guidance is very broad: 'Reference this agent by name or specialty when you need its expertise.' This can cause unintended routing or invocation when a user mentions civil engineering generally, increasing the chance that the wrong skill is activated and its persistent project-specific memory or specialized instructions are applied in an unintended context.

Static analysis

No suspicious patterns detected.