Back to skill

Security audit

discussion-logic-diagnosis

Security checks for vulnerabilities and agentic risk

Overview

This is a non-executable academic writing diagnostic skill with some routing and language-quality caveats but no hidden access, persistence, or unsafe behavior.

Installers should understand this as an academic writing diagnostic helper. It appears safe from a security perspective, but users may want to invoke it with clear context such as a psychology paper Discussion section and specify their preferred output language to avoid broad-trigger or mixed-language confusion.

Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (2)

Vague Triggers

Medium
Confidence
85% confidence
Finding
The trigger set includes broad, natural-language phrases such as "check logic" and "argument check" that can easily match ordinary user requests outside the intended narrow context of psychology-paper Discussion analysis. This can cause unintended routing or invocation of the skill, leading to context confusion, inappropriate analysis, or interception of requests better handled by other skills.

Natural-Language Policy Violations

Medium
Confidence
91% confidence
Finding
This example file is substantially Chinese-language and mixed-language content without offering a language choice or documenting a required locale, which can cause the skill to respond in a language the user did not request. In a diagnosis skill, that creates reliability and accessibility problems and can lead to user confusion or misuse of the guidance, though it is not a code-execution or privilege-escalation issue.

Static analysis

No suspicious patterns detected.