Back to skill

Security audit

OODA Loop

Security checks across malware telemetry and agentic risk

Overview

This is a text-only decision-making framework skill with broad activation wording but no hidden actions, persistence, credentials, or system access.

Before installing, understand that this skill may frame some business, crisis, or incident-response questions through a competitive speed-and-orientation lens. That is disclosed and purpose-aligned, but users should avoid applying it where careful deliberation, safety review, legal judgment, or non-competitive analysis is more appropriate.

Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (1)

Vague Triggers

Medium
Confidence
89% confidence
Finding
The activation text uses broad cues like 'crisis or incident response', 'tempo', and ordinary business situations that can match many unrelated conversations, causing the skill to activate outside its intended scope. In an autonomous or semi-autonomous agent, this can inappropriately steer reasoning toward a competitive speed-first frame and degrade decision quality in contexts where slower, non-competitive analysis is safer.

VirusTotal

64/64 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.