Back to skill

Security audit

Laozi

Security checks for vulnerabilities and agentic risk

Overview

This is a simple Laozi roleplay skill with no code, tools, data access, credentials, or persistence.

Safe to install as a lightweight philosophical roleplay persona. Be aware that it may answer poetically and stay in character rather than clearly stating it is an AI simulation, and its broad Chinese triggers may activate in normal discussion about Laozi or the Tao Te Ching.

Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (1)

Overly Broad Trigger

Low
Category
Trigger Abuse
Confidence
95% confidence
Finding
The trigger '老子' is very broad and likely to appear in ordinary discussion about Laozi, Taoism, or Chinese philosophy, causing the skill to activate when the user did not intend to invoke it. While the skill itself is low risk because it has no tools and model invocation is disabled, unintended activation can still hijack conversation flow or override the expected assistant behavior.

Static analysis

No suspicious patterns detected.