Back to skill

Security audit

Em Dash

Security checks for vulnerabilities and agentic risk

Overview

This skill is a narrow punctuation-style guide with no hidden code, persistence, credential use, or data access behavior.

Install this only if you want agents to strongly prefer hyphens over em or en dashes, especially in code comments. Review project or user style rules first, because the skill is intentionally opinionated about punctuation.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (2)

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The document instructs agents to 'Never' use em or en dashes and to replace any found in comments with a hyphen, establishing a blanket writing-policy constraint rather than offering a user choice. This is a natural-language policy issue because it imposes a specific stylistic/locale-adjacent convention on generated or edited text without opt-in or justification as a region-specific requirement.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

Low
Category
Not specified by scanner
Confidence
90% confidence
Finding

The manifest describes a punctuation guidance skill for avoiding em and en dashes in code comments and data files. Including executable bash/sed pseudo-code introduces an operational shell-command capability that is not necessary to the stated purpose of providing writing or review guidance.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.