Back to skill

Security audit

Fit Scorer

Security checks for vulnerabilities and agentic risk

Overview

This skill is a disclosed influencer scoring aid with limited, purpose-aligned reads and permission-gated writes.

Before installing, confirm you are comfortable with the skill reading relevant campaign inputs, creator records, and optional analytics data for shortlisted influencers. Saving reports or promoting picks requires explicit permission.

Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Findings (1)

Natural-Language Policy Violations

Low
Confidence
92% confidence
Finding
The display name, summary, and description include Chinese text alongside English, but the skill does not indicate that the user can choose their preferred language. Under the policy rule, forcing or assuming a language/locale without explicit opt-in can be a natural-language policy issue.

Static analysis

No suspicious patterns detected.