Back to skill

Security audit

Lithuanian

Security checks for vulnerabilities and agentic risk

Overview

This skill only gives style guidance for writing more natural Lithuanian and does not request sensitive access or run code.

Use this skill when you want casual, natural Lithuanian. For business, official, elderly, or otherwise formal audiences, explicitly ask for formal Lithuanian and 'Jūs' because the skill defaults casual.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Findings (2)

Natural-Language Policy Violations

Medium
Confidence
95% confidence
Finding
The description instructs the skill to 'Write Lithuanian' as a default behavior, which imposes a specific language on users without indicating any choice or opt-in. This is a natural-language locale policy issue because the file does not present the language constraint as optional or region-specific.

Natural-Language Policy Violations

Medium
Confidence
89% confidence
Finding
The instructions require a casual register by default ('Unless explicitly formal: lean casual' and 'Lithuanian internet uses tu'), which enforces a communication style and pronoun choice without confirming user preference. This can violate language/locale policy expectations where formality level should be chosen by or adapted to the user.

Static analysis

No suspicious patterns detected.