Back to skill

Security audit

Margin of Safety

Security checks across malware telemetry and agentic risk

Overview

This is a markdown-only decision-making skill about adding safety buffers, with no executable behavior or hidden access.

Installers should expect an advisory thinking framework, not code. The main practical caution is that it may activate on generic buffer or runway discussions, and any real examples added back into the skill should be scrubbed of confidential details.

Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (1)

Vague Triggers

Medium
Confidence
91% confidence
Finding
The manifest-style description lists activation cues such as "how much buffer to build," "someone wonders if there's enough runway," and later includes the single term "buffer" as a trigger concept. These cues are broad enough to match many everyday conversations outside the intended skill scope, increasing the risk of unintended invocation despite some negative conditions.

VirusTotal

64/64 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.