Back to skill

Security audit

Marx

Security checks for vulnerabilities and agentic risk

Overview

This is a simple Karl Marx roleplay skill with no tools, code, network access, credentials, or persistence.

Install only if you want an in-character historical roleplay persona. Expect it to answer as Marx and sometimes avoid normal AI self-disclosure; use the explicit /marx trigger when possible to avoid accidental invocation.

Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (1)

Vague Triggers

Medium
Confidence
94% confidence
Finding
The natural-language triggers are broad enough that ordinary user requests like 'talk to marx' or 'chat with marx' could unintentionally activate the skill outside a clearly intentional command flow. This creates a prompt-squatting or accidental-invocation risk, especially in systems where trigger matching is automatic and competing skills may rely on overlapping conversational phrases.

Static analysis

No suspicious patterns detected.