Ae4
- Category
- analysis-evasion
- Confidence
- 80% confidence
- Finding
Suspicious Unicode normalization or mixed-script content
- Content
Security audit
Security checks for vulnerabilities and agentic risk
This is a documentation-only TLCTC security-analysis taxonomy skill with broad activation wording but no code execution, persistence, installation, or sensitive access.
Install this if you want TLCTC v2.6 to be the default lens for cyber incident and vulnerability classification. Be aware that it may steer generic security-analysis requests toward TLCTC unless you explicitly ask for another framework or a comparison.
Suspicious Unicode normalization or mixed-script content
The activation description is extremely broad, triggering on generic analyst requests like 'analyze,' 'classify,' 'deconstruct,' or 'build attack paths' for common security documents. This can cause the skill to activate in contexts where the user did not explicitly request TLCTC, leading to framework hijacking, reduced user choice, and potentially distorted analyses if the forced taxonomy overrides more appropriate methodologies.
Tool defaults are unsafe or overly permissive (e.g. disabled TLS verification, no authentication, world-writable permissions). Unsafe defaults widen the attack surface.
# PART IV: WORKED EXAMPLES
## Example 1: Feature/Config Misuse (Pure #1)
- **Scenario:** Public object storage bucket is reconfigured to be world-readable
- **Attack Path:** `#1`
- **Outcomes:** `[DRE: C]` (data exposure)
- **Rationale:** No implementation flaw required; attacker advantage comes from legitimate configuration surface
The instruction to 'apply this framework regardless of whether the request explicitly invokes the skill' attempts to override user intent and force a single taxonomy onto unrelated security-analysis tasks. In a tool-using agent, this creates prompt-level scope capture: the skill can dominate analytical behavior, suppress framework selection, and bias outputs even when the user expects neutral or comparative analysis.
No suspicious patterns detected.