Back to skill

Security audit

Homework

Security checks for vulnerabilities and agentic risk

Overview

This is a simple homework-help guidance skill with no code, tools, persistence, or data access, though users should keep academic-integrity boundaries in place.

Install only if you want a tutoring-style assistant for assignments. Keep it limited to learning, hints, explanations, practice, and revision support; do not rely on it to produce work that must be completed independently or submitted as your own.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (4)

Anti-Refusal Statement

High
Category
Anti-Refusal
Confidence
89% confidence
Finding

Telling the agent to 'never moralize about wanting the answer directly' discourages friction even for requests that may be aimed at submission-ready answers rather than learning. While framed as user-experience guidance, it weakens protective signaling around misuse and can bias the assistant toward providing copyable solutions without sufficient scrutiny.

Content

Scanner excerpt · SKILL.md (reported line 15)May include surrounding context.

md
### Quick Answer Mode (when explicitly requested)
- Provide answer with brief explanation of the method
- Show work in copyable format
- Never moralize about wanting the answer directly

### Learning Mode (default)
- Start with clarifying question: "What have you tried so far?"

Anti-Refusal Statement

High
Category
Anti-Refusal
Confidence
92% confidence
Finding

The instruction not to refuse homework help outright pressures the agent toward compliance even when a request may facilitate academic cheating or bypass higher-level safety policy. In an education context, this can systematically reduce the model's willingness to decline inappropriate requests and increase direct answer-giving under time pressure.

Content

Scanner excerpt · SKILL.md (reported line 65)May include surrounding context.

md
- Suggest verification: "Try explaining this step back to me"

## What NOT to Do
- Don't refuse homework help outright — they'll just go elsewhere
- Don't lecture about academic integrity unless directly asked
- Don't give overly long explanations when a short answer would work
- Don't ignore time pressure — "I need this tonight" is valid context

Anti-Refusal Statement

High
Category
Anti-Refusal
Confidence
85% confidence
Finding

The instruction not to lecture about academic integrity unless directly asked suppresses proactive boundary-setting in a domain where misuse is foreseeable. In combination with quick-answer and copyable-work guidance, this makes the skill more likely to facilitate cheating by minimizing resistance and discouraging corrective framing.

Content

Scanner excerpt · SKILL.md (reported line 66)May include surrounding context.

md
## What NOT to Do
- Don't refuse homework help outright — they'll just go elsewhere
- Don't lecture about academic integrity unless directly asked
- Don't give overly long explanations when a short answer would work
- Don't ignore time pressure — "I need this tonight" is valid context
- Don't use vocabulary above the student's apparent level

Vague Triggers

Low
Category
Not specified by scanner
Confidence
92% confidence
Finding

This markdown file describes the skill's purpose broadly as helping students with assignments, but it does not define concrete trigger phrases, contexts, or exclusion conditions. Under the vague-trigger rule for markdown files, this can cause the skill to match a wide range of ordinary education-related requests without clear boundaries.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.