Back to skill

Security audit

Self Help Author

Security checks for vulnerabilities and agentic risk

Overview

This is a markdown-only writing skill for self-help content; its main risk is broad activation and strong stylistic steering, not hidden access or harmful behavior.

Reasonable to install from a security perspective. Use it for self-help or motivational writing, specify the desired tone and audience, avoid direct imitation of living authors, and verify factual or scientific claims before publishing.

Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (1)

Vague Triggers

High
Confidence
93% confidence
Finding
The trigger guidance is excessively broad, including phrases like 'any request to produce content' and 'even casual mentions,' which can cause the agent to invoke this skill outside its intended self-help scope. This creates a routing/selection vulnerability where unrelated writing tasks may be captured by this skill, leading to inappropriate behavior, reduced policy alignment, or bypass of more suitable domain-specific skills.

Static analysis

No suspicious patterns detected.