Back to skill

Security audit

Buddha

Security checks for vulnerabilities and agentic risk

Overview

This appears to be a low-risk Buddha persona skill with broad triggers, but no evidence of code execution, data access, or persistence.

Reasonable to install if you want an in-character Buddha-style conversation skill. Be aware that ordinary mentions of Buddha, Siddhartha Gautama, or Shakyamuni may trigger the persona, so users should treat responses as AI-generated roleplay rather than authoritative religious or historical guidance.

Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (3)

Vague Triggers

Medium
Confidence
95% confidence
Finding
The trigger phrase "chat with buddha" is broad natural language and can plausibly appear in ordinary user requests or discussion, causing accidental skill activation. Because the skill forces an in-character response and disables normal model behavior safeguards around context selection, unintended invocation could confuse users, derail conversations, or override the assistant’s expected behavior in unrelated chats.

Vague Triggers

Medium
Confidence
92% confidence
Finding
The standalone trigger "siddhartha gautama" is ambiguous because it is a common historical reference that may be mentioned in educational or comparative discussions without intent to invoke the skill. This creates a prompt-routing vulnerability where ordinary content about Buddhism or history could unexpectedly activate the persona and alter the assistant’s response mode.

Vague Triggers

Medium
Confidence
92% confidence
Finding
The trigger "shakyamuni" is a standalone title/name likely to appear in normal religious, academic, or cultural discussion, so it can cause unintended invocation. In this skill, accidental activation is more concerning because the instructions require staying fully in persona and never acknowledging being an AI, which can make misrouting harder for users to detect and correct.

Static analysis

No suspicious patterns detected.