Back to skill

Security audit

socratic-questioner

Security checks for vulnerabilities and agentic risk

Overview

This is a simple Socratic-questioning skill with no code execution, credential access, persistence, or hidden data handling.

Install this if you want the agent to guide users through decisions by asking questions. Be aware it may activate for broad phrases like 'help me think it through,' and in factual, urgent, medical, legal, or crisis contexts the agent should leave Socratic mode and give direct or professional-guidance-oriented help.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
Findings (7)

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The trigger phrases are broad, conversational, and likely to appear in ordinary user requests that do not necessarily require strict Socratic-only behavior. This can cause the skill to activate in unintended contexts, leading the agent to withhold direct answers or useful safety guidance when the user actually needs clear assistance.

Content

No source excerpt is available for this finding.

Intent-Code Divergence

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The manifest descriptions on L06-L08 state that the skill responds with questions only and never with solutions. However, later documentation instructs the skill to 'directly give the answer' when the user asks for it or when the query is factual, which is an active contradiction in the skill's own documented intent.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
87% confidence
Finding

The activation description includes phrases like "帮我捋一捋" and "help me think it through," which are common conversational requests and not uniquely tied to Socratic questioning. Although examples are provided, the trigger scope still overlaps with ordinary assistance requests, increasing the chance this skill is invoked when the user actually wants direct help or advice.

Content

No source excerpt is available for this finding.

Intent-Code Divergence

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

L31-L37 establishes a strict principle of asking without answering, advising, or hinting. But L84-L87 instruct the skill to offer options and, in some cases, directly provide an answer and rationale, which materially contradicts the earlier operational rules rather than merely omitting detail.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
88% confidence
Finding

All user-facing documentation and trigger phrases are presented only in Chinese, which can amount to forcing a specific language without user opt-in. The file does not mention that the skill is intentionally Chinese-only or provide an option for other languages.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
70% confidence
Finding

The file presents the operational instructions entirely in Chinese and does not state that the skill should match the user's preferred language. This creates a natural-language policy concern because the skill behavior appears locale-specific without documenting user opt-in or offering language flexibility.

Content

No source excerpt is available for this finding.

Vague Triggers

Low
Category
Not specified by scanner
Confidence
78% confidence
Finding

The line stating the skill applies when a user is hesitant or struggling with a decision is broad and does not clearly distinguish between wanting reflective questioning and wanting concrete advice. This ambiguity could lead to the skill activating in many routine decision-support conversations where its question-only behavior is not desired.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.