Back to skill

Security audit

fasaha

Security checks for vulnerabilities and agentic risk

Overview

This is a disclosed Arabic proofreading skill with broad activation and small local self-updating notes, but no hidden, destructive, credential, or exfiltration behavior was found.

Installers should know this skill may activate automatically for longer Arabic output and may update its own local glossary, register profile, and correction log. Review those files if you want tighter control over tone preferences or learned terminology.

Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (2)

Vague Triggers

Medium
Confidence
88% confidence
Finding
The trigger conditions are very broad and include common Arabic-writing and translation requests, which can cause the skill to activate in many ordinary contexts without explicit user intent. In an agent system, over-broad automatic invocation can override task prioritization, create unnecessary transformations of user content, and increase the chance of the skill being applied where it is not appropriate, especially when it also references self-maintained state files.

Vague Triggers

Medium
Confidence
91% confidence
Finding
The proactive guidance to run the skill before any Arabic prose longer than 2–3 sentences is ambiguous and expansive, making the skill effectively self-invoking across a large class of normal outputs. This can lead to unintended rewriting of model responses, conflict with other skills or user instructions, and hidden modification of tone/register beyond what the user asked for.

Static analysis

No suspicious patterns detected.