Back to skill

Security audit

Skillet Special

Security checks for vulnerabilities and agentic risk

Overview

The only evidenced issue is broad activation wording that may route ordinary planning requests into this skill, not malicious or hidden behavior.

Install if you want this skill to help with repo-grounded planning or opportunity analysis. Be aware it may activate for broad planning prompts; use explicit wording when you do or do not want this workflow, and review any suggested repo-wide analysis before allowing follow-up edits.

Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (1)

Vague Triggers

Medium
Confidence
92% confidence
Finding
The trigger phrases are broad enough to match many ordinary planning or ideation requests, which can cause this skill to activate outside its intended niche. That creates a routing/control weakness: users asking general questions about missing functionality or next steps may be steered into this specialized workflow unexpectedly, potentially suppressing more appropriate skills and causing unintended repo-wide analysis.

Static analysis

No suspicious patterns detected.