Back to skill

Security audit

Fact-Checking Explainers

Security checks for vulnerabilities and agentic risk

Overview

This is a text-only fact-checking workflow that is coherent with its stated purpose and does not show hidden, destructive, persistent, or credential-seeking behavior.

Before installing, understand that this skill may automatically run during explainer drafting or review and may inspect cited sources or relevant code to verify claims. That behavior is expected for the skill, but avoid using it on sensitive drafts or private repositories unless you want those materials included in the fact-checking process.

Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (1)

Vague Triggers

Medium
Confidence
88% confidence
Finding
The skill enables implicit invocation while its description and default prompt are broad enough that an agent may auto-trigger it in loosely related contexts without clear user intent or sufficient scoping. For a fact-checking skill, this can cause unintended handling of sensitive drafts, sources, or codebases and may let adversarial content steer when verification runs or what materials are pulled into scope.

Static analysis

No suspicious patterns detected.