Back to skill

Security audit

Ai Humanizer 2.1.0

Security checks for vulnerabilities and agentic risk

Overview

This skill is an offline writing-analysis tool that matches its stated purpose, with some cautions about overconfident AI-authorship labels and honest use.

Install only if you want a local heuristic writing-pattern tool. Do not treat its scores as proof that a human or AI wrote something, and do not use the humanizing suggestions to misrepresent authorship, identity, or personal experience. If you run the developer tooling, pin and audit dev dependencies first.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Vulnerability Patterns
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
Findings (23)

Tp4

High
Category
MCP Tool Poisoning
Confidence
99% confidence
Finding

The declared description describes a natural-language processing skill for detecting and rewriting AI-generated text. The actual code chunk does not implement any text processing, detection, rewriting, or statistical analysis. Instead, it only configures ESLint for JavaScript source and test files. This is a materially different primary purpose and unrelated to the declared behavior, so it is a clear mismatch.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
99% confidence
Finding

There is a clear mismatch between the declared description and the actual code. The description claims a substantial natural-language processing capability for detecting and humanizing AI-generated text, including multiple detectors and statistical analysis. The provided code does none of that; it merely configures the Vitest test framework. This is not a supporting implementation detail of the described functionality, but an unrelated infrastructure/configuration file with a materially different purpose.

Content

No source excerpt is available for this finding.

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 109)May include surrounding context.

md
echo "Your text here" | node src/cli.js score

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 112)May include surrounding context.

md
echo "Your text here" | node src/cli.js score

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 115)May include surrounding context.

md
echo "Your text here" | node src/cli.js score

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 118)May include surrounding context.

md
echo "Your text here" | node src/cli.js score

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 121)May include surrounding context.

md
echo "Your text here" | node src/cli.js score

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 124)May include surrounding context.

md
echo "Your text here" | node src/cli.js score

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 127)May include surrounding context.

md
echo "Your text here" | node src/cli.js score

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
70% confidence
Finding

Without declared permissions the skill's intent is opaque and cannot be validated.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The activation text is broad enough to trigger on many ordinary editing or writing requests, which can cause the agent to apply this skill outside the user's intent. In context, that is risky because the skill is designed to rewrite prose to evade AI-writing signals, so over-triggering could lead to unwanted transformation of content, loss of authorial intent, or assistance in bypassing AI-detection policies.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

The summary text makes categorical claims such as 'The text looks human-written' and labels content as 'heavily AI-generated,' which can overstate the reliability of heuristic pattern matching. In a user-facing skill specifically marketed to detect and humanize AI text, this can mislead users into treating probabilistic stylistic signals as factual authorship determinations, creating trust, compliance, or moderation harms.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
89% confidence
Finding

The label helpers describe metrics as 'human-like' or 'AI-like' as if these correlations are definitive, despite being weak stylistic proxies that vary by genre, length, and editing history. Because this skill's purpose is to score text for AI detection, such authoritative labels increase the risk that downstream users or systems will over-rely on noisy indicators in decisions about authenticity or policy enforcement.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
83% confidence
Finding

The user-facing strings assign normative labels such as 'Mostly human-sounding' and 'Heavily AI-generated' as the default interpretation of output. While not a hardcoded non-English locale, this is natural-language policy-relevant messaging that imposes a single evaluative framing on users without opt-in or contextual justification.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The style tip explicitly encourages adding first-person phrases such as "I found" and "In my experience" as a humanization tactic, without requiring that those statements be true. In a tool whose purpose is to make AI-generated text appear human, this can facilitate deceptive impersonation of personal experience, fabricated authorship, or misleading testimonial-style content.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
89% confidence
Finding

The natural-language comment explicitly states this is an "English heuristic," which indicates the skill's text analysis is language-constrained. Under the policy, locale-specific behavior should either be user-selectable or clearly documented and justified as region/language-specific; this file contains the constraint but no opt-in or justification for applying it generally.

Content

No source excerpt is available for this finding.

Unpinned Dependencies

Low
Category
Supply Chain
Confidence
40% confidence
Finding

Dependencies lack version pinning, allowing potential malicious package updates. Consider pinning versions.

Content

Scanner excerpt · package.json (reported line 41)May include surrounding context.

json
"url": "https://github.com/brandonwise/humanizer"
  },
  "devDependencies": {
    "@eslint/js": "^9.39.2",
    "eslint": "^9.0.0",
    "prettier": "^3.0.0",
    "vitest": "^3.0.0"

Unpinned Dependencies

Low
Category
Supply Chain
Confidence
40% confidence
Finding

Dependencies lack version pinning, allowing potential malicious package updates. Consider pinning versions.

Content

Scanner excerpt · package.json (reported line 42)May include surrounding context.

json
},
  "devDependencies": {
    "@eslint/js": "^9.39.2",
    "eslint": "^9.0.0",
    "prettier": "^3.0.0",
    "vitest": "^3.0.0"
  },

Unpinned Dependencies

Low
Category
Supply Chain
Confidence
40% confidence
Finding

Dependencies lack version pinning, allowing potential malicious package updates. Consider pinning versions.

Content

Scanner excerpt · package.json (reported line 43)May include surrounding context.

json
"devDependencies": {
    "@eslint/js": "^9.39.2",
    "eslint": "^9.0.0",
    "prettier": "^3.0.0",
    "vitest": "^3.0.0"
  },
  "engines": {

Unpinned Dependencies

Low
Category
Supply Chain
Confidence
73% confidence
Finding

vitest is declared with a broad caret range and is also flagged separately as having known advisories in some releases. Because this is a devDependency, the primary risk is to developer workstations or CI systems running tests rather than end users of the humanizer skill, but vulnerable test tooling can still enable file read or code execution in those environments.

Content

Scanner excerpt · package.json (reported line 44)May include surrounding context.

json
"@eslint/js": "^9.39.2",
    "eslint": "^9.0.0",
    "prettier": "^3.0.0",
    "vitest": "^3.0.0"
  },
  "engines": {
    "node": ">=18.0.0"

Unverifiable Dependency: vitest has 3 known advisory(ies) (CVE-2026-47429 (When Vitest UI server is listening, arbitrary file can be read and executed); CVE-2026-84373 (Vitest: Path Traversal / Arbitrary File Read via @vitest/mocker Redirect Mock); CVE-2025-24964 (Vitest allows Remote Code Execution when accessing a malicious website while Vit)), but the manifest does not pin a version, so it is unknown whether the installed release is affected

Low
Category
Supply Chain
Confidence
86% confidence
Finding

The manifest includes vitest without a pinned version, and the analyzer notes multiple known advisories affecting some vitest releases, including arbitrary file read and possible code execution scenarios. In this skill's context, vitest is development-only, so the risk is reduced compared with a production dependency, but it still meaningfully threatens local developer environments and CI runners.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
52% confidence
Finding

This code file contains natural-language test descriptions about non-English handling, and the phrase 'handles non-English gracefully' references language behavior without documenting user choice or locale policy. However, because this is only a test file and does not force a language or locale, the concern is weak and low confidence.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
78% confidence
Finding

This test file encodes style rules that replace specific English phrases like "in order to" and "due to the fact that" with preferred English alternatives. Because the skill behavior appears to normalize language according to a fixed English style without any visible language or locale choice, it may conflict with the policy against forcing a specific language/locale without user opt-in.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.