Ae1
- Category
- analysis-evasion
- Confidence
- 100% confidence
- Finding
Referenced artifact was not completely inspected
- Content
md 
Security audit
Security checks for vulnerabilities and agentic risk
This skill is a straightforward Acme document-branding guide with helper scripts, with some scope and locale caveats but no evidence of malicious behavior.
Install this only where Acme branding should be applied, especially for external communications. Be prepared to override the default US currency/date conventions and broad 'any document' guidance for other locales, internal drafts, or non-Acme work.
Referenced artifact was not completely inspected

The skill description says it applies branding to "all generated documents," which creates an extremely broad activation scope with no clear trigger boundaries or exclusions. In an agent setting, this can cause the skill to interfere with unrelated tasks, override user-preferred formats, and introduce unintended behavior across many document-generation contexts.
Skill enables autonomous high-impact decisions without human-in-the-loop verification. Critical operations (destructive commands, financial transactions, data deletion) should require explicit user confirmation.
### Prohibited Elements
Never use:
- Clip art or stock photos without approval
- Comic Sans, Papyrus, or decorative fonts
- Rainbow colors or gradients
- Animations or transitions (unless specified)
The instruction to apply the skill "when creating any document" is an ambiguous, catch-all trigger that encourages activation in nearly every writing workflow. This is dangerous because a broadly scoped skill can silently modify outputs, conflict with higher-priority user instructions, and reduce predictability of agent behavior.
The number-formatting logic returns currency values using a fixed '$' symbol, which imposes a specific locale/currency convention in natural-language-visible output. The file does not offer user opt-in or configuration for other locales or currencies, so this can violate language/locale policy requirements.
Line L090 says to always use "Month DD, YYYY," which imposes a specific locale format as a universal rule. This is a natural-language locale policy issue because the file later acknowledges multiple regional date formats, so the unconditional instruction is inconsistent and not framed as an opt-in or justified constraint.
The document standards require '$X,XXX.XX' currency and 'Month DD, YYYY' dates, which impose a specific locale convention. Because the file does not offer user opt-in or explain a region-specific requirement, this is a natural-language locale policy concern.
No suspicious patterns detected.