Back to skill

Security audit

Wu Wei (无为, Effortless Action)

Security checks for vulnerabilities and agentic risk

Overview

This is a text-only coaching skill with broad activation wording but no commands, persistence, data access, or hidden behavior.

Before installing, consider that this skill may steer ambiguous coaching or management conversations toward a subtractive, non-forcing lens. It is appropriate as a reflective framework, but users should avoid applying it where urgent intervention, domain training, or concrete execution is needed.

Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (2)

Vague Triggers

Medium
Confidence
90% confidence
Finding
The activation metadata includes broad natural-language phrases like 'let it happen' and 'stop forcing' that can appear in many ordinary conversations outside the intended philosophical or coaching context. This can cause accidental skill invocation, leading the agent to apply an introspective non-intervention framework when a different skill or more direct assistance would be more appropriate.

Vague Triggers

Medium
Confidence
86% confidence
Finding
The 'When to Use' section includes vague triggers such as 'flow,' 'stop forcing,' and similar broad concepts without sufficiently strict boundary checks. In practice, this increases the chance the skill will activate on ambiguous user language and steer responses toward passivity or subtraction even when the user needs concrete execution, escalation, or domain-specific guidance.

Static analysis

No suspicious patterns detected.