Back to skill

Security audit

Maus HTML Summary

Security checks for vulnerabilities and agentic risk

Overview

This is a disclosed text-to-HTML summarization skill with no evidence of hidden execution, credential access, persistence, or data exfiltration.

Install if you want an agent helper that turns provided text into an illustrated standalone HTML explainer. Be aware that implicit invocation may route broad article, transcript, or text-summary requests through this skill, so use explicit invocation or review the selected skill when working with sensitive private content.

Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (1)

Vague Triggers

Medium
Confidence
92% confidence
Finding
The default prompt says to use the skill to turn "this article, transcript, or text" into an HTML explainer, which defines the content types broadly without clarifying trigger boundaries or exclusions. In a manifest file, this can create an overly expansive activation scope for many everyday summarization requests rather than a narrowly constrained invocation pattern.

Static analysis

No suspicious patterns detected.