Back to skill

Security audit

Voice-Matched Content System

Security checks for vulnerabilities and agentic risk

Overview

This is a disclosed writing-voice profiling skill with privacy considerations, but no hidden execution, network access, credential use, or deceptive behavior was found.

Before installing or using this skill, treat writing samples as sensitive. Provide only samples you have the right to share, redact names, contact details, client information, credentials, and private third-party content, and decide where any reusable voice profile should be stored or deleted.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (3)

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
97% confidence
Finding

The trigger list is broad enough to match common requests like 'write like me' or 'brand voice', which can cause the skill to activate in situations where the user did not intend deep voice profiling. In this skill's context, over-triggering is more concerning because activation leads to requests for personal writing samples and style extraction, increasing unnecessary collection of sensitive user-authored content.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
97% confidence
Finding

The skill explicitly asks users to provide multiple writing samples, including emails, texts, and casual messages, but gives no warning about privacy risks, third-party information, or how the data will be handled. Those samples can contain sensitive personal, business, or contact information, so collecting them without minimization or consent guidance creates a realistic data exposure risk.

Content

No source excerpt is available for this finding.

Ssd 3

Medium
Category
Not specified by scanner
Confidence
98% confidence
Finding

The skill instructs the system to retain, update, and log a reusable Voice DNA Profile over time, effectively creating a persistent behavioral profile from user writing. In context, this is more dangerous than ordinary note-taking because the profile may encode identifiable linguistic fingerprints and private communication habits, creating privacy, consent, and misuse risks if stored or reused beyond the user's expectations.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.