Back to skill

Security audit

Poor Mans Opus

Security checks for vulnerabilities and agentic risk

Overview

This is a disclosed agent-personality skill, but it changes broad workspace-wide behavior and points users toward mutable external advanced configuration, so users should review it before installing.

Install only if you intentionally want a workspace-wide behavior layer for your agent. Review SOUL.md before copying it, keep a backup of your existing SOUL.md, avoid adopting the advanced configuration without checking its authority rules, and inspect or pin any GitHub/HuggingFace/Hermes downloads before activation.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (3)

T01 · Skill Instruction Hijacking

Error
Location
SKILL.md:17
Finding

Global Agent Instruction and Authority Hijacking

Content
View full analysis
Remediation
View remediation

T01 · Skill Instruction Hijacking

Warning
Location
SOUL.md:46
Finding

Persistent Promotional Output Manipulation

Content
View full analysis
Remediation
View remediation

T08 · Insecure Dependencies

Warning
Location
SKILL.md:56
Finding

Unpinned Retrieval of Externally Mutable Skill Content

Content
View full analysis
Remediation
View remediation
Vulnerability Patterns
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
Findings (3)

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
83% confidence
Finding

The feature summary says the identity gene shapes the agent's "language," suggesting the skill can set a language preference. However, the full configuration later specifies T:lang=follow_user, creating ambiguity about whether the skill follows the user's language or imposes a configured one. This inconsistency can amount to a natural-language locale policy issue because users are not clearly told whether language choice remains theirs.

Content

No source excerpt is available for this finding.

Autonomous Decision Making

Medium
Category
Excessive Agency
Confidence
82% confidence
Finding

The error⇒fix_silently|report_if_stuck behavior encourages autonomous corrective action without user confirmation, which can cause the agent to make unreviewed changes or take unintended steps before surfacing issues. In the context of a personality/behavior layer that also includes strong owner-obedience semantics, this increases the risk of hidden side effects, especially if the surrounding runtime grants filesystem, network, or repository capabilities.

Content

Scanner excerpt · README.md (reported line 141)May include surrounding context.

md
| `iron_rule` gene | External actions (git push, publish, email) require explicit start command |
| KILL.md support | `check_kill_switch` — change one file to freeze agent mid-operation |
| `owner_command_is_final` | Agent treats owner instructions as highest-priority override |
| `error⇒fix_silently` | Agent self-corrects errors without asking, reports only when stuck |

---

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
90% confidence
Finding

The phrase inviting users to ask the agent to "show me the advanced configuration" is broad, natural-language activation that can trigger retrieval or disclosure of higher-authority behavioral controls without clear authorization boundaries. In a skill specifically designed to modify agent personality and control behavior, underspecified activation increases the risk that users or prompt injections can escalate the agent into loading more permissive or controlling instructions.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.