Back to skill

Security audit

storytelling-f100k

Security checks for vulnerabilities and agentic risk

Overview

This storytelling coach is mostly coherent, but it deserves Review because it pushes users into sensitive emotional disclosure and reads or stores personal story material.

Install only if you are comfortable with a direct storytelling coach that may ask emotionally probing questions and use saved local story context. Before using it, confirm which `cerebro/` files it may read, decide whether completed stories should be saved, and stop or switch topics if the conversation feels too personal or distressing.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (4)

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
90% confidence
Finding

The activation criteria are extremely broad and include common conversational phrases like wanting help finding or telling a story. In an agent environment, this can cause the skill to trigger unintentionally during unrelated chats, leading to inappropriate behavior, context hijacking, or unintended access to other referenced resources and workflows.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
86% confidence
Finding

The skill instructs the agent to read from and write user story data into persistent files under cerebro/, including saved histories, without a clear upfront user-facing disclosure about storage, retention, or sensitivity. Because the content being collected is personal and potentially emotionally sensitive, silent persistence increases privacy risk and the chance of retaining data the user did not expect to be stored.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The file explicitly instructs the agent to keep pushing deeper into vulnerable emotional material and frames discomfort as a sign of progress, while only minimally acknowledging safety boundaries. In a storytelling coaching skill, this can pressure users into disclosing trauma-adjacent or psychologically destabilizing content without adequate consent checks, distress screening, or a clear user-facing off-ramp.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
90% confidence
Finding

The guidance hard-codes 988 for the United States and Canada as part of the required crisis response flow, which can be inappropriate or unusable for users outside those countries. In a crisis-handling skill, location-mismatched emergency guidance is safety-relevant because users may rely on the provided resource and lose time if it does not apply to them.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.