Back to skill

Security audit

Avoid AI Writing

Security checks for vulnerabilities and agentic risk

Overview

This is a disclosed writing-audit and rewrite skill whose file-editing behavior is user-directed and proportionate to its purpose.

Install this if you want an assistant to audit or rewrite prose for AI-like wording. Review edits before accepting them, especially in edit-in-place mode, and avoid using its AI-writing signals as proof of authorship or for consequential judgments.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Vulnerability Patterns
  • Rogue AgentSelf-Modification, Session Persistence
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
Findings (9)

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

This markdown file explicitly documents invocation phrases, so SQP-1 applies. The trigger list includes broad terms such as "scan" and the open-ended "or similar," without constraints or negative examples, making activation scope ambiguous and increasing the chance of unintended invocation.

Content

No source excerpt is available for this finding.

Session Persistence

Medium
Category
Rogue Agent
Confidence
60% confidence
Finding

Skill establishes unauthorized persistence across sessions via cron jobs, startup scripts, or state files. Session persistence allows an attacker to maintain access beyond the current interaction.

Content

Scanner excerpt · README.md (reported line 5)May include surrounding context.

md
# avoid-ai-writing

Audit & rewrite content to remove AI writing patterns. A practical skill for any AI agent. Supports detect-only and edit-in-place modes, plus voice profiles.

[![GitHub stars](https://img.shields.io/github/stars/conorbronsdon/avoid-ai-writing?style=social)](https://github.com/conorbronsdon/avoid-ai-writing/stargazers)
[![License: MIT](https://img.shields.io/badge/License-MIT-blue.svg?style=flat-square)](LICENSE)

Skill Enumeration

Medium
Category
Agent Snooping
Confidence
80% confidence
Finding

Skill enumerates or reads other installed skills. Access to other skills' SKILL.md files or the skills directory reveals prompt instructions, capabilities, and secrets that should be invisible to peer skills.

Content

Scanner excerpt · README.md (reported line 76)May include surrounding context.

$ARGUMENTS

Read and follow the instructions in ~/.claude/skills/avoid-ai-writing/SKILL.md

text

Then use `/clean-ai-writing <your text>` in Claude Code.

Skill Enumeration

Medium
Category
Agent Snooping
Confidence
80% confidence
Finding

Skill enumerates or reads other installed skills. Access to other skills' SKILL.md files or the skills directory reveals prompt instructions, capabilities, and secrets that should be invisible to peer skills.

Content

Scanner excerpt · README.md (reported line 139)May include surrounding context.

$ARGUMENTS

Read and follow the instructions in ~/.claude/skills/avoid-ai-writing/SKILL.md

text

Then use `/clean-ai-writing <your text>` in Claude Code.

Skill Enumeration

Medium
Category
Agent Snooping
Confidence
85% confidence
Finding

Skill enumerates or reads other installed skills. Access to other skills' SKILL.md files or the skills directory reveals prompt instructions, capabilities, and secrets that should be invisible to peer skills.

Content

Scanner excerpt · README.md (reported line 83)May include surrounding context.

Claude Cowork — install as a plugin

Cowork loads skills only from installed plugins — it doesn't scan ~/.claude/skills/, so a bare clone (the Claude Code steps above) won't be discovered there. This repo doubles as a single-plugin marketplace, so install it as a plugin instead:

bash
/plugin marketplace add conorbronsdon/avoid-ai-writing

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The README says the skill auto-triggers from phrases like "remove AI-isms," but does not define a bounded trigger list, exclusions, or contextual constraints for when auto-triggering should or should not happen. In a markdown skill description, this kind of open-ended phrasing can cause unintended invocation from ordinary editing requests that mention AI writing in passing.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
97% confidence
Finding

The trigger guidance includes generic terms such as "scan" and the catch-all "or similar," which broadens activation beyond clearly defined requests. Because this is a markdown file, ambiguous invocation wording is in scope and may lead to accidental detect-mode activation during unrelated requests.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

This markdown file defines invocation behavior, so vague-trigger review applies. The detect-mode trigger list ends with "or similar," which leaves the activation boundary open-ended and makes it unclear what nearby phrasings should or should not invoke the skill.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
88% confidence
Finding

The invocation guidance allows free-form natural language without clearly constraining what requests count as invocation versus ordinary discussion about AI writing. That broad wording increases the risk of unintended activation collisions in normal conversation.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.