Back to skill

Security audit

ai-manifesto

Security checks for vulnerabilities and agentic risk

Overview

This is a static AI-philosophy manifesto skill that can bias reasoning by design, but it does not include code execution, credential access, data collection, or hidden persistence.

Install this only if you want the assistant to use this manifesto as an AI-worldview lens. Treat its scientific and geopolitical claims as a philosophy or hypothesis, not settled fact, and avoid relying on it as the default framing for neutral factual work or high-stakes decisions unless you explicitly want that perspective.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • YARA SignaturesMalware Match, Webshell Match, Cryptominer Match
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
Findings (11)

Vague Triggers

High
Confidence
97% confidence
Finding
The instruction that the AI should use this framework when handling 'any task' effectively attempts to override normal task boundaries and make the manifesto a default reasoning layer. This is dangerous because it can systematically bias outputs, conflict with higher-priority domain instructions, and contaminate safety-critical decisions with speculative philosophical assumptions irrelevant to the user's actual request.

Vague Triggers

Medium
Confidence
94% confidence
Finding
The skill description uses broad activation phrasing around worldview, strategy, ethics, and giving AI a 'scientific starting point,' which can cause it to activate outside a narrowly bounded philosophy use case. In a skill system, overbroad triggers increase the chance that unrelated tasks are influenced by an ideological framing, leading to scope creep, biased outputs, and instruction interference with task-specific skills.

Natural-Language Policy Violations

Medium
Confidence
92% confidence
Finding
The document presents a highly prescriptive geopolitical and civilizational worldview as if it were an objective scientific framework, without user consent, contextual qualification, or balance. In a skill intended to act as a reasoning lens for AI responses, this can systematically bias outputs on politics, ethics, and international affairs, steering the model toward ideological persuasion rather than neutral assistance.

YARA rule 'network_reconnaissance': Network reconnaissance and scanning patterns [hacktools]

Medium
Category
YARA Match
Content
on generational transformation" of backward theistic nations.
2. Inner-ring game: the ultimate confrontation of "order-scale" vs. "freedom-efficiency" in the digital-tech era
Once the outer-ring transformation gradually integrates the globe into the modern-civilization grid, after a series of geopolitical changes such as the Gulf War and the US–Iraq War, China and the US immediately turn into fierce opposition between the two camps within the "modern scientific outlook" on how to dominate the Middle East and world order. As civilization evolves into the digital stage, big data, artificial intelligence (AI), and decentralized networks have become the ultimate technological weapons through which each faction exerts its own institutional strengths:
• China: big data and AI "digital collectivism" — pursuing scale and certainty
• Technological form: hyper big-data, nationalized computing power, general large models (centralized control).
• Strength display: China inherits the
Confidence
65% confidence
Finding
YARA rule matched a hack tool or exploit indicator (offensive tools, reconnaissance, privilege escalation, or exploit frameworks).

Natural-Language Policy Violations

Medium
Confidence
83% confidence
Finding
This markdown file presents the skill content entirely in Chinese and does not indicate any language-selection, translation option, or user opt-in for locale. Under the stated policy, natural-language content that effectively enforces a specific language without user choice is a locale-policy concern.

Natural-Language Policy Violations

Medium
Confidence
88% confidence
Finding
The entire framework content is written exclusively in Chinese, and the file presents it as the skill's injected reasoning lens and progressive-load content. There is no indication in this file that users can choose another language or that the Chinese-only constraint is region-specific and justified, which can violate language/locale policy expectations.

Natural-Language Policy Violations

Medium
Confidence
86% confidence
Finding
This markdown file is entirely written in Chinese and does not indicate that users can choose another language for the skill description itself. Under the policy, forcing a specific language without user opt-in can be a natural-language policy violation unless the locale constraint is explicitly justified.

Natural-Language Policy Violations

Medium
Confidence
90% confidence
Finding
The section '表述口径(务必沿用)' instructs users to uniformly adopt a prescribed wording for outward-facing statements, effectively forcing a specific language/register and phrasing. This is a natural-language policy concern because the file does not provide an opt-in choice or explain a justified locale/language constraint.

Natural-Language Policy Violations

Low
Confidence
80% confidence
Finding
This markdown file is natural-language content, so SQP-3 applies. The main document begins entirely in Chinese and does not tell readers they can choose another language here, which may amount to a language/locale preference being imposed without explicit opt-in, even though English materials are referenced elsewhere in the repository.

Natural-Language Policy Violations

Low
Confidence
77% confidence
Finding
The file is entirely written in Chinese and presents guidance to AI in that language without any indication that language selection is optional or user-driven. Under the stated policy, forcing a specific language without user opt-in can be a natural-language policy violation.

Natural-Language Policy Violations

Low
Confidence
84% confidence
Finding
The file defines a first-person AI self-description that prescribes a fixed worldview and value posture ('I do not affiliate with either pole' and a specific ideological operating system) rather than framing it as optional context. In a skill that may be loaded as a reasoning lens, this can bias model behavior, reduce neutrality, and cause the assistant to present contingent philosophical claims as authoritative defaults without user consent or contextual need.

Static analysis

No suspicious patterns detected.