Back to skill

Security audit

Skills

Security checks for vulnerabilities and agentic risk

Overview

This skill is a straightforward writing-style analysis and imitation helper with no hidden execution, persistence, credential use, or unrelated data access.

Installers should understand that this skill may activate for many writing-style or imitation requests. Use it with content you have rights to analyze, avoid deceptive impersonation, and do not use it to reproduce copyrighted text verbatim.

Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (2)

Vague Triggers

Medium
Confidence
91% confidence
Finding
The skill declares trigger conditions so broadly that it can activate on many ordinary requests about analyzing tone, style, or imitating writing, even when a dedicated skill is not clearly intended. Over-broad routing can cause unintended capability invocation, bypass normal task scoping, and increase the chance of assisting with sensitive style imitation or copyrighted-text transformation without sufficient checks.

Vague Triggers

Medium
Confidence
88% confidence
Finding
The natural-language examples are expansive and lack exclusions, making this skill likely to capture general writing-assistance requests that should remain in the default assistant flow. In security terms, ambiguous dispatch increases the attack surface: users can trigger specialized behavior through loose phrasing, including style replication workflows that may raise impersonation, abuse, or copyright-adjacent concerns.

Static analysis

No suspicious patterns detected.