Back to skill

Security audit

Rebuttal Letter Strategist

Security checks for vulnerabilities and agentic risk

Overview

This skill is a small academic rebuttal helper with no evidence of hidden access, persistence, network use, or data exfiltration.

This appears safe to install for academic rebuttal drafting. Expect a simple command-line helper, not a full document-processing workflow; users may need to supply inputs manually because the documentation overstates or inconsistently names some parameters.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Vulnerability Patterns
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (2)

Intent-Code Divergence

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

The Parameters section says the skill takes structured inputs like criticism, response_type, and evidence, implying rebuttal-generation functionality. However, the only demonstrated script interface is python scripts/main.py --help, and the surrounding workflow text instead discusses generic input/output paths and config editing, with no indication that these rebuttal parameters are actually accepted by the packaged script. This is a documentation-level contradiction about what the code entry point does.

Content

No source excerpt is available for this finding.

Intent-Code Divergence

Medium
Category
Not specified by scanner
Confidence
84% confidence
Finding

The Returns and Example sections claim the skill produces a professionally toned rebuttal response and transforms wording such as "We disagree" into a softer academic phrase. Elsewhere, the implementation and execution sections describe a generic packaged workflow that validates requests, edits config, and produces an output artifact, without evidence that the code actually performs this rebuttal-specific text transformation. This creates an intent-versus-implementation documentation mismatch.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.