Back to skill

Security audit

Fictional Companion Forge

Security checks for vulnerabilities and agentic risk

Overview

This prompt-only skill creates fictional-character companion profiles and shows no hidden code, credential access, or external data use.

Install this if you want help creating fictional-character companion profiles. Review generated companions for unwanted intensity, romance, violence, or canon-inference issues, and avoid using the skill to impersonate real people or present fan-inferred traits as official canon.

Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (1)

Vague Triggers

Medium
Confidence
92% confidence
Finding
The trigger description is very broad and includes generic requests like 'let me talk to this character' or 'generate an agent based on this fictional role,' which could cause the skill to activate for loosely related prompts outside its intended scope. In an agent-routing system, this can lead to misselection, causing the model to produce persona-driven companion outputs when the user may have intended analysis, discussion, or other safer/non-impersonation tasks.

Static analysis

No suspicious patterns detected.