Back to skill

Security audit

Narrative Quality Auditor

Security checks for vulnerabilities and agentic risk

Overview

This skill is a scoped brand-narrative auditing guide that reads user-provided marketing evidence and only writes audit artifacts after explicit authorization.

Installers should expect this skill to inspect marketing canon, surfaces, and experiment evidence supplied or available in the working context. Allow persistence only when you want an audit report saved under the stated memory/audits/narrative path.

Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Findings (1)

Natural-Language Policy Violations

Medium
Confidence
87% confidence
Finding
The display name, summary, and description include Chinese text alongside English, but the skill does not state whether bilingual output is optional or user-selected. Because the instructions do not offer a language choice or explain a justified locale restriction, this can conflict with a policy requiring language or locale opt-in.

Static analysis

No suspicious patterns detected.