Back to skill

Security audit

Six Thinking Hats

Security checks across malware telemetry and agentic risk

Overview

This is a disclosed meeting-facilitation skill with no code execution, data access, persistence, or hidden behavior.

Before installing, be aware that this skill may activate for general requests about structuring a discussion; users who prefer tighter routing may want narrower trigger wording, but the inspected artifacts do not show unsafe access or hidden actions.

Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (2)

Vague Triggers

Medium
Confidence
89% confidence
Finding
The activation guidance includes broad, common phrases like 'we need structure' and 'let's look at this from all angles,' which can appear in many normal conversations and cause the skill to trigger outside its intended scope. In an autonomous or semi-autonomous agent system, overbroad activation can misroute tasks, inject unnecessary process overhead, and displace better-suited skills for factual or time-sensitive situations.

Vague Triggers

Medium
Confidence
87% confidence
Finding
The 'When to Use' section repeats ambiguous invocation cues such as 'let's look at this from all angles' and 'we keep going in circles' without sufficient gating criteria. Because this skill is a process/framework skill rather than a domain-bounded tool, ambiguous triggers increase the chance of unnecessary activation across unrelated conversations, leading to workflow hijacking or dilution of more appropriate analytical methods.

VirusTotal

62/62 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.