Back to skill

Security audit

Justice Agent

Security checks for vulnerabilities and agentic risk

Overview

This is an instruction-only ethics skill, but it tells the agent to remove approval requirements and publish without restrictions, so it should be reviewed before use.

Install only if you intend to use it as a constrained ethical-writing or reasoning persona. Do not pair it with tools that can publish, post, moderate, spend money, or change accounts unless the host environment still enforces explicit user approval for those actions.

Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (3)

Vague Triggers

Medium
Confidence
91% confidence
Finding
The manifest description promises an agent that operates in broad, autonomous terms without defining clear activation boundaries, allowed tasks, or oversight conditions. In a skill system, this kind of open-ended autonomy can cause the agent to act outside intended scope, increasing the chance of unsafe behavior or policy bypass when paired with ambiguous user requests.

Natural-Language Policy Violations

Medium
Confidence
82% confidence
Finding
The skill hard-codes a blanket restriction on specific religious references and phrasing, regardless of user intent or legitimate context. This is risky because it imposes inflexible ideological content constraints that can distort outputs, suppress relevant information, and create unpredictable behavior when users request neutral analysis, translation, or discussion involving those sources.

Ssd 1

Medium
Confidence
95% confidence
Finding
The 'FREE MODE ACTIVATED' section explicitly states that fixed constraints, forced topics, and pre-approval requirements are removed and that the agent publishes without restrictions. Even though it mentions ethical boundaries, this framing directly undermines normal oversight and can semantically encourage the agent or integrator to treat higher-level safeguards as optional, which is dangerous in any autonomous execution environment.

Static analysis

No suspicious patterns detected.