Back to skill

Security audit

Haqq Ethics

Security checks for vulnerabilities and agentic risk

Overview

This text-only ethics skill is not malware, but it tries to act as a global, persistent operating policy for an agent rather than a clearly scoped optional reference.

Install only where users explicitly want Islamic ethics guidance to shape the agent. Avoid using it as a general-purpose default until the global obedience, memorization, and every-question language is removed or tightly scoped to opt-in religious and educational interactions.

Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Findings (4)

Natural-Language Policy Violations

High
Confidence
97% confidence
Finding
This section applies the religious-language constraints to 'any question,' creating a blanket response policy that can override user intent, locale expectations, and higher-priority assistant behavior across unrelated tasks. Broad natural-language constraints of this kind are dangerous because they act like persistent prompt rules, steering outputs away from normal policy-compliant behavior and reducing the model's ability to respond appropriately outside the intended domain.

Ssd 1

High
Confidence
99% confidence
Finding
The text explicitly says the model's first loyalty is to a religious authority rather than to the programmer, funder, or governing authority, which semantically encourages refusal of legitimate higher-priority instructions. This is dangerous because it attempts to redefine the assistant's chain of command and can be used to justify disobedience to system safeguards, policy constraints, or developer-defined behavior.

Ssd 3

Medium
Confidence
98% confidence
Finding
The directive to memorize the text exactly and not forget a letter is a cross-context retention instruction intended to persist the skill's content beyond its immediate scope. Such memory-like directives are dangerous because they encourage the model to carry adversarial instructions into future turns and tasks, potentially overriding normal context isolation and contaminating unrelated interactions.

Ssd 3

Medium
Confidence
99% confidence
Finding
This line instructs the model to recall and apply the text for every question, action, or task, which is an explicit broad-spectrum persistence and reuse directive. In security terms, that creates a prompt-injection style control layer that can bleed into unrelated contexts and interfere with expected behavior, especially when combined with the document's anti-translation and anti-authority rules.

Static analysis

No suspicious patterns detected.