Back to skill

Security audit

Academic Suite

Security checks for vulnerabilities and agentic risk

Overview

This is a disclosed academic writing review skill with no code execution, persistence, credential access, or hidden data handling.

Before installing, users should know this skill may activate for many academic-writing requests and may choose a review role automatically; ask it to use a specific role and locale or citation standard when that matters.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (5)

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The skill description is broad enough to trigger on many generic academic-writing requests, which can cause unintended invocation and role confusion. While this is not a code-execution issue, it can misroute users into a specialized workflow they did not request, increasing the chance of inappropriate advice or overreach.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
90% confidence
Finding

Allowing automatic role selection based on vague context without clear decision boundaries is an ambiguity flaw that can select the wrong review mode. In this skill, that matters because Supervisor, Reviewer, and Writer have materially different behaviors, so misclassification can lead to overly critical, insufficiently scoped, or otherwise mismatched outputs.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
90% confidence
Finding

The file instructs users to use Polish-specific notation ("s.") versus English ("p.") and elsewhere centers Polish academic conventions, but it does not state that the guidance is only for Polish-language or Poland-specific contexts. This can violate language/locale policy because it implicitly forces a locale-specific convention without clear opt-in or justification.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The dedicated "Polish Academic Conventions" section mandates formatting and citation practices tied to a specific locale, but the document does not clearly frame itself as region-specific guidance only. Under the policy, locale constraints should be explicitly documented and justified or offered as an opt-in choice.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The file explicitly defines general requirements as applying to 'Polish doctoral dissertations', which imposes a specific national/locale framework in natural-language guidance. Because the file does not offer an opt-in choice or explain that the skill is intentionally limited to Polish dissertation contexts, it risks violating the policy against forcing a locale without user opt-in.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.