Back to skill

Security audit

Replyher Skill

Security checks for vulnerabilities and agentic risk

Overview

This communication-coaching skill appears purpose-aligned, but users should redact private or sensitive chat content before sharing it.

Before installing or using it, redact names, contact details, workplace secrets, financial or health information, and any third-party private messages you do not have permission to share.

Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Findings (1)

Missing User Warnings

Medium
Confidence
91% confidence
Finding
The README explicitly encourages users to paste messages and full chat threads, and also advertises screenshot recognition, but provides no warning about sensitive personal data, third-party privacy, or workplace/confidential information. In a communication-coaching skill, users are likely to submit intimate, identifying, or regulated content, so the absence of privacy guidance materially increases the risk of oversharing and unintended disclosure.

Static analysis

No suspicious patterns detected.