Back to skill

Security audit

Book Multi Lens

Security checks for vulnerabilities and agentic risk

Overview

This skill is a plain Markdown reasoning aid for analyzing quotes or viewpoints, with no code execution, data access, persistence, or hidden behavior found.

Install this if you want the assistant to automatically structure quote, book, or idea discussions into balanced perspectives. Be aware that it may trigger on broadly phrased quote or note discussions, and its language defaults may not match every multilingual preference.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (4)

Vague Triggers

High
Category
Not specified by scanner
Confidence
95% confidence
Finding

The trigger criteria are overly broad: they include generic phrases like asking to analyze a viewpoint and even any pasted quote or notes. This can cause the skill to activate for many ordinary conversations where the user did not explicitly ask for this behavior, leading to prompt hijacking of the assistant’s response style and unintended handling of unrelated content.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The trigger description is broad enough to activate on many ordinary discussions about quotes, books, or opinions, increasing the chance the skill runs when the user did not clearly ask for it. Over-broad activation can cause unintended behavior, override user intent, and make the assistant apply this skill in contexts where its framing or constraints are not appropriate.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

The skill forces a default language policy of English unless the user writes in Chinese, which can conflict with user preference and system-level language expectations. While not a direct security exploit, it can degrade user control and cause inappropriate behavior in multilingual settings.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
97% confidence
Finding

The instruction to prioritize Chinese unless the user writes in English overrides normal language preference handling and can produce responses in a language the user did not request. This is dangerous because it reduces user control, can degrade accessibility and trust, and may cause the assistant to ignore system- or platform-level language expectations.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.