Back to skill

Security audit

grill-the-plan

Security checks for vulnerabilities and agentic risk

Overview

This skill only adds a pre-work planning and confirmation workflow, with no executable code or hidden data access.

Install this if you want the agent to slow down and confirm plans before multi-step or risky work. Be aware it may activate more often than a command-only skill, and non-Chinese users may want a translated or language-negotiating version.

Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (2)

Vague Triggers

Medium
Confidence
92% confidence
Finding
The activation phrases are broad and overlap with ordinary conversation such as '先细化', '先确认再动手', and '别急着干'. This can cause the skill to trigger unintentionally in unrelated contexts, changing agent behavior and potentially blocking or reshaping user workflows without explicit intent.

Natural-Language Policy Violations

Medium
Confidence
86% confidence
Finding
The skill content is written to operate in Chinese without offering a user-language choice or documenting a justified locale restriction. This can lead to misunderstanding of confirmation prompts, parameters, or risks, especially because the skill gates execution on explicit user approval.

Static analysis

No suspicious patterns detected.