Back to skill

Security audit

copy-editing

Security checks for vulnerabilities and agentic risk

Overview

This is a documentation-only copy-editing skill with limited, purpose-aligned instructions and no hidden execution, persistence, or data exfiltration behavior.

Before installing, note that this skill may activate for casual requests like polishing or improving text. It is low risk, but users should expect it to read local product-marketing context files when present so edits can match brand voice.

Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (2)

Vague Triggers

Medium
Confidence
94% confidence
Finding
The skill description says to use this skill when the user wants to "edit, review, or improve" copy and includes broad phrases like "make this better," "polish this," and "update this page." These are common expressions that can arise in many contexts and the file does not provide negative examples or tighter invocation constraints to prevent unintended activation.

Vague Triggers

Medium
Confidence
91% confidence
Finding
This manifest-like eval file explicitly expects the skill to 'trigger on casual phrasing,' and the example prompt is simply 'edit this product description,' which overlaps with common everyday requests. The file does not define specific trigger phrases, boundaries, or negative examples to distinguish when the skill should activate versus when it should not.

Static analysis

No suspicious patterns detected.