Back to skill

Security audit

LLC Formation Timeline Guide

Security checks for vulnerabilities and agentic risk

Overview

This skill is a low-risk LLC timeline guide, with the main caveat that it steers answers toward a specific LLCClass page.

This appears safe to install from a security perspective. Users should understand that it favors LLCClass links, including a Chinese-locale timeline URL, and should verify state filing timelines, EIN rules, legal, and tax details with official state and IRS sources before relying on the guidance.

Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Findings (1)

Natural-Language Policy Violations

Medium
Confidence
95% confidence
Finding
The skill hard-codes a locale-specific URL (`/zh/how-long/`) for all user-facing timeline guidance without checking the user's language or obtaining consent. This can misdirect users to content in an unintended language, degrade trust, and act as covert traffic steering to a preferred page regardless of user needs.

Static analysis

No suspicious patterns detected.