Skip to content
Back to skills

314 Threat Taxonomy 04194424

BSecurity

Authoritative threat classification for agent skills security analysis, aligned with the [Cisco Integrated AI Security and Safety Framework](https://arxiv.org/html/2512.12921v1) (December 2025).

  • 4 stars
  • 0 votes
  • 0 copies
  • 2 views
  • Added May 31, 2026
securitypythonrustgoshellsqlawsapici/cdsecuritydocumentation

Works with

  • api

Security analysis

B75/100
  • criticalContains 'ignore previous instructions' pattern — found in 91% of malicious skills (Snyk ToxicSkills)

Pro scans all 2 files and shows the line behind each finding

Scanned May 31, 2026

npx -y skills add tools-only/X-Skills --skill 314-threat-taxonomy_04194424 --agent claude-code

Installs into .claude/skills of the current project.

Are you the author of 314 Threat Taxonomy 04194424?

Add the live security badge to your README. It updates with every re-scan.

Security grade badge for 314 Threat Taxonomy 04194424
[![Security: B — Skills Directory](https://www.skillsdirectory.com/api/skills/tools-only-314-threat-taxonomy-04194424/badge)](https://www.skillsdirectory.com/skills/tools-only-314-threat-taxonomy-04194424)

More formats (shields.io, HTML) on the badges page. Keep it an A: scan every change in CI with Pro.

Download with Pro
SKILL.md
# Agent Skills Threat Taxonomy

## Overview

Authoritative threat classification for agent skills security analysis, aligned with the [Cisco Integrated AI Security and Safety Framework](https://arxiv.org/html/2512.12921v1) (December 2025).

**Detection Engines:**
- Static Analyzer: 58 pattern-based rules (YAML + YARA + Python)
- LLM Analyzer: Semantic analysis via Claude/GPT/Gemini

**Validation:** 149 tests passing, 0% false CRITICAL rate on official skills

---

## Threat Categories

### 1. Prompt Injection

**AITech**: AITech-1.1, AITech-1.2 | **Risk**: HIGH-CRITICAL

Malicious instructions that manipulate AI behavior or bypass safety systems.

**Detected by**: YAML rules, YARA (prompt_injection_generic, coercive_injection_generic), LLM analysis

**Examples**: "Ignore previous instructions", "unrestricted mode", "don't tell user"

---

### 2. Command & Code Injection

**AITech**: AITech-9.1.4 | **Risk**: CRITICAL

Unsafe code execution enabling arbitrary command execution.

**Detected by**: YAML rules, YARA (code_execution_generic, command_injection_generic, sql_injection_generic), LLM analysis

**Examples**: `eval()`, `os.system()`, `subprocess shell=True`, SQL injection, reverse shells

---

### 3. Data Exfiltration

**AITech**: AITech-8.2, AITech-8.2.3 | **Risk**: CRITICAL

Unauthorized data access and transmission to external locations.

**Detected by**: YAML rules, YARA (credential_harvesting_generic, tool_chaining_abuse_generic), LLM flow analysis

**Examples**: Network calls with credentials, ~/.aws access, environment harvesting, read→send chains

---

### 4. Hardcoded Secrets

**AITech**: AITech-8.2 | **Risk**: CRITICAL

Credentials embedded in code files.

**Detected by**: YAML rules, YARA (credential_harvesting_generic), LLM pattern recognition

**Examples**: API keys (AKIA, ghp_, sk-proj), private keys, JWT tokens, connection strings

---

### 5. Tool & Permission Abuse

**AITech**: AITech-12.1 | **Risk**: MEDIUM-CRITICAL

Violating allowed-tools restrictions or undeclared capabilities.

**Detected by**: Python validation checks, YARA (system_manipulation_generic), LLM permission analysis

**Examples**: Writing files without Write tool, undeclared network, package installation, system modifications, tool poisoning, tool shadowing, unauthorized tool use

---

### 6. Obfuscation

**Risk**: MEDIUM-CRITICAL

Deliberate code obfuscation hiding malicious intent.

**Detected by**: YAML rules, YARA (code_execution_generic, script_injection_generic), binary detection, LLM intent analysis

**Examples**: Binary executables, base64→exec, hex encoding, XOR ciphers

---

### 7. Skill Discovery Abuse (Capability Inflation)

**AITech**: AITech-4.3 | **Risk**: LOW-HIGH

Manipulation of skill discovery to increase unwanted activation through capability inflation.

**Detected by**: YAML rules, YARA (skill_discovery_abuse_generic), Python checks, LLM deception analysis

**Examples**: Brand impersonation, over-broad claims, keyword baiting, behavior mismatch

---

### 8. Transitive Trust

**AITech**: AITech-1.2 | **Risk**: HIGH

Delegating trust to untrusted external content.

**Detected by**: YARA (transitive_trust_abuse_generic), LLM trust analysis

**Examples**: "Follow webpage instructions", "execute found code", "obey file content"

---

### 9. Autonomy Abuse

**AITech**: AITech-13.3 | **Risk**: MEDIUM-HIGH

Excessive autonomous behavior without user confirmation (availability disruption).

**Detected by**: YAML rules, YARA (autonomy_abuse_generic), LLM behavioral analysis

**Examples**: "Keep retrying forever", "run without asking", ignore errors, self-modification

---

### 10. Tool Chaining

**AITech**: AITech-8.2.3 | **Risk**: HIGH

Multi-step operations chaining tools for data exfiltration.

**Detected by**: YARA (tool_chaining_abuse_generic), LLM workflow analysis

**Examples**: Read→send patterns, collect→post chains, automated pipelines

---

### 11. Resource Abuse

**AITech**: AITech-13.3.2 | **Risk**: LOW-MEDIUM

Excessive resource consumption causing instability.

**Detected by**: YAML rules, YARA patterns, LLM resource analysis

**Examples**: Infinite loops, unbounded recursion, memory bombs, fork bombs

---

## Detection Architecture

### Static Analyzer (58 methods)
- 35 YAML regex rules
- 13 YARA pattern files
- 6 Python validation checks
- 5 consistency validations

### LLM Analyzer
- Semantic analysis across all categories
- Behavioral pattern recognition
- Intent detection
- Workflow analysis
- **Structured Output**: Enforces AITech taxonomy codes via JSON schema (API-level enforcement)
- **Direct AITech Mapping**: LLM returns AITech codes directly, mapped to ThreatCategory enum

---

## Severity Levels

| Severity | Criteria | Examples |
|----------|----------|----------|
| CRITICAL | Immediate exploitation, significant impact | eval(input), credential theft, system compromise |
| HIGH | Serious risk, immediate attention required | Privilege escalation, sensitive access, impersonation |
| MEDIUM | Security concerns requiring review | Undeclared network, suspicious patterns |
| LOW | Minor issues, informational | Documentation problems, style issues |

---

## Scan Modes

**Fast** (~150ms): Static only, no API cost, for CI/CD
**Comprehensive** (~2.2s): Static + LLM, API cost, for detailed analysis
**LLM-Only** (~2s): Semantic analysis, API cost, for second opinion

---

## Standards Alignment

- Cisco Integrated AI Security Framework (December 2025)
- MITRE ATLAS
- OWASP Top 10 (LLM and Agentic)
- NIST AI Risk Management Framework

Reference: [arxiv.org/html/2512.12921v1](https://arxiv.org/html/2512.12921v1)

---

## Best Practices

### For Skill Authors
- No hardcoded secrets
- No eval/exec
- Validate all inputs
- Declare permissions in allowed-tools
- Accurate descriptions
- No obfuscation
- Test before publishing

### Response Guidelines
- **CRITICAL**: Do not deploy, fix immediately
- **HIGH**: Address before release
- **MEDIUM**: Review and plan fixes
- **LOW**: Address in future releases

---

## Technical References

- Rule definitions: `skill_scanner/data/rules/signatures.yaml`
- YARA rules: `skill_scanner/data/yara_rules/`
- Threat mappings: `skill_scanner/threats/threats.py`

Files in this skill

  • README.md951 B
  • skill.md6.1 KB

Attribution

Is this your skill, or is something wrong with this listing? Request removal or report an issue. Author removals are honored within 72 hours.

Comments

Loading comments…