Back to skill

Security audit

conversation-visualizer

Security checks for vulnerabilities and agentic risk

Overview

The skill mostly matches its stated chat-visualization purpose, but it requests an unexplained skill-management capability while handling session history and generated files.

Review before installing if you do not want a skill that can read session history and write visual exports. Use it only on chats you are comfortable summarizing, review generated files before sharing them, and consider removing or justifying the unused skill_workshop permission.

Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (1)

Vague Triggers

Medium
Confidence
91% confidence
Finding
The invocation phrases are very broad and overlap with common user requests such as summarizing or visualizing a chat. That can cause unintended activation of a skill that has access to session history and file writing, increasing the chance of unnecessary exposure of conversation contents into generated artifacts or local files.

Static analysis

No suspicious patterns detected.