Back to skill

Security audit

Thucydides's Trap

Security checks for vulnerabilities and agentic risk

Overview

This is a text-only analysis skill for geopolitical and business rivalry questions, with no code execution, hidden data access, or persistence.

This skill is appropriate to install as a text-only reasoning aid. Users should treat its geopolitical and business-risk examples as analytical framing, not authoritative current intelligence, and may want the publisher to add an instruction to preserve the user's preferred language.

Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Findings (1)

Natural-Language Policy Violations

Medium
Confidence
84% confidence
Finding
The instruction says 'In Coach mode, respond one step at a time' but provides no allowance for the user's preferred language or locale. Because the skill content is entirely English and the response behavior is prescribed without opt-in or language choice, this can violate a language/locale policy requiring user preference or explicit justification.

Static analysis

No suspicious patterns detected.