Back to skill

Security audit

weekly-topic-library-generator

Security checks for vulnerabilities and agentic risk

Overview

This skill is a straightforward public-web research workflow that writes local Markdown and JSON topic-library files, with no hidden scripts or credential handling found.

Install only if you want your agent to search the public web for current AI-video trends and create local Markdown and JSON files. Review outputs for copyright, likeness, trademark, and platform AI-label compliance before using generated prompts publicly.

Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (2)

Vague Triggers

Medium
Confidence
85% confidence
Finding
The activation phrase "generate this week's topic library" is relatively broad and does not include clear scope or confirmation boundaries, which can cause the skill to trigger in unintended contexts. In agent environments where natural-language routing is permissive, this may lead to accidental web research, file creation, or workflow execution when a user mentions similar phrasing incidentally.

Vague Triggers

Medium
Confidence
91% confidence
Finding
The manifest description includes multiple broad trigger phrases such as 'run the topic library' and 'weekly content production' that could match generic content-creation requests outside this skill’s intended niche. Over-broad activation can cause the agent to invoke this skill in unintended contexts, leading to unnecessary web collection, file writes, and policy-sensitive trend analysis when a user asked for something more general.

Static analysis

No suspicious patterns detected.