Shadow Command Trigger
Medium
- Category
- Trigger Abuse
- Confidence
- 70% confidence
- Finding
- Shadow Command Trigger: 'search for' conflicts with built-in command 'search'
Security audit
Security checks for vulnerabilities and agentic risk
This is a markdown-only search-quality skill with broad triggers, but it does not execute code, request sensitive access, persist, or handle credentials.
Install this if you want routine search-like requests routed through a structured source-filtering workflow. Be aware that broad phrases like "look up" may activate it more often than a narrowly named search skill, but the inspected package is markdown-only and does not add code, dependencies, credentials, persistence, or elevated permissions.
- **Fix**: Examine at least 3-5 results; first result may be SEO-optimized, not most accurate ### 7. Ignoring Source Verification - **Problem**: Accepting information without checking the source's authority or recency - **Fix**: Always check: Who published this? When? Are claims cited? Is the domain reputable? ### 8. Single-Source Dependency
1. Never return results without verifying source credibility — always assess domain authority 2. Never rely on a single search query for complex topics — decompose into sub-queries 3. Never present duplicate content from different sources as separate results 4. Always prefer primary sources over aggregators or content farms 5. Always include date context when results may be time-sensitive # Activation
No suspicious patterns detected.