Back to skill

Security audit

Tsinkening AI Resume

Security checks for vulnerabilities and agentic risk

Overview

This is a markdown-only fictional AI-founder profile skill with no code execution, credentials, persistence, or system access.

Install this only if you want a fictional AI career-profile prompt. Treat the named person, products, social metrics, income numbers, and advice as simulated content, not verified facts; for best results, ask the agent to answer only from the included dossier.

Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (1)

Vague Triggers

Medium
Confidence
91% confidence
Finding
The skill explicitly says users can ask 'any question' about the persona, which creates overly broad activation/response scope and can cause the skill to engage outside its intended domain. In context this is not directly enabling code execution or data exfiltration, but it can lead to unintended triggering, confusing outputs, or prompt-scope bleed into unrelated conversations.

Static analysis

No suspicious patterns detected.