Back to skill

Security audit

伏矢·路径魄

Security checks for vulnerabilities and agentic risk

Overview

This is a low-risk, instruction-only planning skill with some broad activation wording users should be aware of.

Install this if you want the agent to produce structured plans for complex tasks. Expect it may volunteer planning or decomposition for broad project requests; review any separately installed dependent skills before relying on them.

Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (1)

Vague Triggers

Medium
Confidence
89% confidence
Finding
The trigger guidance is broad enough that many ordinary requests involving planning or multi-step work could activate the skill unintentionally. This can cause the agent to override user expectations, inject unsolicited planning behavior, or route prompts into this skill when a narrower or safer skill would be more appropriate.

Static analysis

No suspicious patterns detected.