Back to skill

Security audit

podcast-digest

Security checks for vulnerabilities and agentic risk

Overview

This is a podcast analysis skill with broad activation wording but no hidden access, persistence, destructive behavior, or credential use.

Safe to install for podcast summaries and study notes. Use explicit prompts when you want it invoked, ask for your preferred output language if needed, and avoid giving private transcripts or unpublished podcast details unless you are comfortable with possible external search for supplemental context.

Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (2)

Vague Triggers

Medium
Confidence
91% confidence
Finding
The trigger language is broad enough that ordinary mentions of podcasts, audio learning, or note-taking could automatically invoke this skill even when the user did not ask for podcast analysis. Over-broad activation increases the chance of incorrect routing, unnecessary use of network/search behavior, and processing of content under assumptions the user did not intend.

Natural-Language Policy Violations

Medium
Confidence
86% confidence
Finding
The skill metadata and instructions strongly bias behavior toward Chinese output without offering a user-language fallback or preserving the user's preferred language. This can cause incorrect or unsafe task execution in multilingual settings, including misunderstanding user intent, producing inaccessible output, or conflicting with higher-priority system behavior about matching user language.

Static analysis

No suspicious patterns detected.