Back to skill

Security audit

Manager Development Spectrum

Security checks for vulnerabilities and agentic risk

Overview

This is a markdown-only coaching framework for manager development; its sensitive profiling aspects are disclosed and partly bounded, but users should treat outputs as coaching hypotheses, not employment judgments.

Install only if you want an agent to use a developmental-stage coaching framework. Use it with explicit consent where possible, keep evidence private, avoid sharing stage labels with managers or HR as performance ratings, and do not use it for hiring, promotion, discipline, or legal/clinical assessment.

Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (2)

Vague Triggers

Medium
Confidence
93% confidence
Finding
The activation text is broad enough to trigger on common leadership or coaching conversations, which can cause the agent to apply a psychologically interpretive framework when the user may only want routine management advice. In this skill, over-triggering is risky because the workflow proceeds into quasi-assessment of a person's developmental stage and can steer subsequent advice based on inferred internal traits rather than explicit user intent.

Natural-Language Policy Violations

Low
Confidence
90% confidence
Finding
The skill directs the agent to assign stage labels, infer blind spots, and discuss developmental assessments of identifiable people or roles without requiring documented consent, privacy constraints, or jurisdiction/HR-policy checks. Even though the file includes some cautionary language, it still operationalizes sensitive psychological-style profiling that could be shared in organizational contexts and used in employment decisions, creating privacy, fairness, and misuse risks.

Static analysis

No suspicious patterns detected.