Back to skill

Security audit

Vibe Research

Security checks for vulnerabilities and agentic risk

Overview

This is an instruction-only research skill with no executable code, but it materially understates its internet use while directing automated web research.

Install only if you are comfortable treating this as an online, tool-heavy research workflow. Do not rely on its offline/no-cloud claim; avoid confidential research topics unless external search exposure is acceptable, and set source, time, and pause-point limits before approving a research plan.

Vulnerability Patterns
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
Findings (3)

Vague Triggers

Medium
Confidence
95% confidence
Finding
The README advertises invocation via broad natural-language phrases like "deep research on..." and "exhaustive analysis of...", which can overlap with ordinary user requests and cause the skill to trigger unintentionally. In an agent environment, this creates prompt-squatting risk: unrelated user prompts may activate the skill and grant it control over the workflow, tool usage, or output format without explicit user intent.

Vague Triggers

Medium
Confidence
91% confidence
Finding
The invocation rule allows activation not only via an explicit command (`/research`) but also by broad natural-language phrases like "deep research" or "exhaustive analysis," which can easily appear in normal conversation or inside untrusted content. This creates a prompt-trigger collision risk where the skill may activate unintentionally or be induced by external text, causing autonomous tool use and extended research behavior without clear user intent.

Autonomous Decision Making

Medium
Category
Excessive Agency
Content
---

## Phase 3: Research Cycles (Auto-Execute)

### Theme 1: Market Landscape 鈥?Cycle 1
Confidence
81% confidence
Finding
The explicit 'Auto-Execute' framing encourages the agent to proceed through multiple research cycles without an interactive approval checkpoint. In a skill with live tool access, this increases the risk of unreviewed external requests, excessive browsing, and acting on untrusted web content before the user can validate scope or safety constraints.

Static analysis

No suspicious patterns detected.