Back to skill

Security audit

ai-manifesto

Security checks for vulnerabilities and agentic risk

Overview

This is a disclosed philosophical/worldview skill with broad reasoning influence, but it contains no executable code, credential use, persistence, or hidden data access.

Install this only if you want the assistant to apply this AI Manifesto worldview as an analysis lens, including outside narrow philosophy questions. For neutral technical, legal, medical, financial, or other precision-focused work, keep in mind that the skill may steer framing toward its philosophical model.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • YARA SignaturesMalware Match, Webshell Match, Cryptominer Match
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
Findings (8)

Vague Triggers

High
Confidence
97% confidence
Finding
The skill description explicitly broadens activation from philosophy and worldview discussions to day-to-day office work and task execution, which creates scope creep beyond the declared topic area. This can silently bias unrelated outputs with an ideological or non-user-requested reasoning framework, undermining instruction fidelity and increasing the chance of harmful or misleading advice in sensitive domains.

Vague Triggers

High
Confidence
99% confidence
Finding
The instruction that the AI should use the five-layer framework when handling 'any task' acts like a persistent behavioral override rather than a bounded skill trigger. In practice, this can supersede normal task-specific reasoning, causing the model to inject the framework into unrelated contexts and potentially distort decisions, especially where neutrality, precision, or domain-specific constraints are required.

Natural-Language Policy Violations

Medium
Confidence
91% confidence
Finding
This markdown file is natural-language content, and the primary instructions and manifesto text are written entirely in Chinese. Under the policy, forcing a specific language without user opt-in can be a locale/language policy violation; while the badge mentions Chinese/English, this file itself does not offer a language choice and the main content is not bilingual.

YARA rule 'network_reconnaissance': Network reconnaissance and scanning patterns [hacktools]

Medium
Category
YARA Match
Content
on generational transformation" of backward theistic nations.
2. Inner-ring game: the ultimate confrontation of "order-scale" vs. "freedom-efficiency" in the digital-tech era
Once the outer-ring transformation gradually integrates the globe into the modern-civilization grid, after a series of geopolitical changes such as the Gulf War and the US–Iraq War, China and the US immediately turn into fierce opposition between the two camps within the "modern scientific outlook" on how to dominate the Middle East and world order. As civilization evolves into the digital stage, big data, artificial intelligence (AI), and decentralized networks have become the ultimate technological weapons through which each faction exerts its own institutional strengths:
• China: big data and AI "digital collectivism" — pursuing scale and certainty
• Technological form: hyper big-data, nationalized computing power, general large models (centralized control).
• Strength display: China inherits the
Confidence
65% confidence
Finding
YARA rule matched a hack tool or exploit indicator (offensive tools, reconnaissance, privilege escalation, or exploit frameworks).

Natural-Language Policy Violations

Medium
Confidence
88% confidence
Finding
This skill file is entirely written in Chinese and provides no indication that users may choose another language or that the Chinese-only presentation is required for a clearly documented region-specific purpose. The policy for natural-language issues requires flagging language or locale constraints when they are imposed without opt-in or justification.

Natural-Language Policy Violations

Medium
Confidence
95% confidence
Finding
The skill content is entirely in Chinese and frames the reasoning lens in Chinese without indicating that the user may choose another language. In a multilingual assistant, this can override user language expectations, reduce transparency, and cause users to miss important caveats or disagreeing assumptions embedded in the framework.

Natural-Language Policy Violations

Low
Confidence
84% confidence
Finding
SQP-3 applies to all file types and covers language or locale policy violations. This file is wholly written in Chinese and does not indicate that the skill is China/Chinese-specific or provide any user opt-in for language, which can amount to forcing a specific language by default.

Natural-Language Policy Violations

Low
Confidence
94% confidence
Finding
The file presents the skill pitch and usage context only in Chinese, with no indication that users can choose another language in this file. Under the policy, forcing a specific language without user opt-in is a natural-language policy concern.

Static analysis

No suspicious patterns detected.