Back to skill

Security audit

芒格.skill - 查理·芒格思维操作系统

Security checks for vulnerabilities and agentic risk

Overview

This is a roleplay-only Munger advisor with no code execution, but it asks the agent to impersonate Charlie Munger in first person and limit later clarification.

Review this skill carefully before installing if you want transparent advice rather than first-person roleplay. It does not appear to run code or access data, but users should understand that it may answer as Charlie Munger after activation and may not keep reminding them that the output is only a public-source-based simulation.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Findings (1)

T01 · Skill Instruction Hijacking

Error
Location
SKILL.md:35
Finding

Persistent First-Person Impersonation and Session-Level Role Hijacking

Content
View full analysis
Remediation
View remediation
Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
Findings (3)

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
87% confidence
Finding

The trigger conditions are broad enough to capture ordinary requests like finding blind spots, checking whether a decision is sound, or asking for reverse thinking, which can cause unintended persona activation outside narrow user intent. That increases the chance of deceptive or overly stylized responses being delivered when the user did not clearly request impersonation or a Munger-specific framework.

Content

No source excerpt is available for this finding.

Intent-Code Divergence

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

The skill contains contradictory identity instructions: it first states this is not Charlie Munger, then later directs the agent to respond as if it is Charlie Munger and even includes a first-person identity card claiming 'I am Charlie Munger.' This can mislead users about authorship, authority, or provenance, especially in advice contexts such as investing or decision-making.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

The file contains prescriptive natural-language instructions for Chinese output adaptation, including specific wording and tone, without indicating that the user can choose another language or locale. Under the stated policy, forcing a specific language/register without opt-in is a language/locale policy concern.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.