Back to skill

Security audit

Ghost Theme Builder

Security checks for vulnerabilities and agentic risk

Overview

This skill is a Ghost CMS theme helper whose file access, commands, and references fit its stated theme-building purpose.

Install this if you want an AI assistant to work on Ghost themes. Expect it to inspect and modify theme files and suggest or run theme validation/build commands when you ask for implementation or review work.

Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (1)

Vague Triggers

Medium
Confidence
88% confidence
Finding
The README states the skill 'loads automatically when you ask the AI to build, review, or debug a Ghost theme,' which is a broad auto-activation trigger. Broad activation increases the chance the skill is invoked in contexts the user did not explicitly intend, exposing its instructions and any bundled content to unrelated conversations or causing unintended behavior.

Static analysis

No suspicious patterns detected.