Back to skill

Security audit

AI Paraphraser

Security checks for vulnerabilities and agentic risk

Overview

This skill is a Review item because it is explicitly designed to rewrite text to evade AI detectors, including academic detector systems, though it contains no executable code or persistence.

Review carefully before installing. The skill has low technical system risk, but it is built to help text avoid AI-detection and similarity systems; use or rewrite it only for legitimate editing, and avoid using it to misrepresent authorship, bypass academic integrity checks, or evade platform and workplace review controls.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (9)

Missing User Warnings

High
Category
Not specified by scanner
Confidence
98% confidence
Finding

The description openly promotes bypassing AI detectors but provides no warning about academic misconduct, fraud, or policy violations. That omission increases the likelihood of misuse by normalizing evasion as a standard feature and failing to set safety boundaries for high-risk contexts such as education, publishing, or compliance workflows.

Content

No source excerpt is available for this finding.

Ssd 2

Medium
Category
Not specified by scanner
Confidence
99% confidence
Finding

This section explicitly instructs the model to rewrite AI-generated text to 'bypass AI detectors' and frames detector avoidance as a product goal. The context makes this more dangerous, not less, because the entire skill is purpose-built for concealment of provenance rather than legitimate editing, enabling academic cheating, fraud, and policy evasion at scale.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
97% confidence
Finding

The skill defines very broad invocation phrases such as generic requests to 'rewrite,' 'paraphrase,' or 'polish text,' which can cause the tool to activate in ordinary writing contexts without surfacing the high-risk evasion purpose. In this file, that overbreadth is especially dangerous because the skill’s stated objective is to bypass AI detectors, so benign writing requests may be silently routed into integrity-evasion behavior.

Content

No source excerpt is available for this finding.

Ssd 2

Medium
Category
Not specified by scanner
Confidence
97% confidence
Finding

The workflow operationalizes evasion by telling the system to identify detector-triggering patterns and systematically alter them while preserving meaning. These are actionable tactics for defeating heuristic detection systems, making the skill a practical evasion playbook rather than a neutral paraphrasing guide.

Content

No source excerpt is available for this finding.

Ssd 2

Medium
Category
Not specified by scanner
Confidence
98% confidence
Finding

Aggressive mode directs deliberate insertion of 'human writing characteristics,' irregular phrasing, and structural changes specifically to hide AI-origin signals. This is dangerous because it moves beyond ordinary paraphrasing into intentional obfuscation designed to defeat provenance analysis and detection controls.

Content

No source excerpt is available for this finding.

Ssd 2

Medium
Category
Not specified by scanner
Confidence
97% confidence
Finding

The quality checklist requires elimination of AI markers and reduction of detectable similarity, explicitly measuring success by whether the content is harder to flag. That turns the skill into a verification loop for evasion, increasing reliability of misuse in plagiarism, authorship fraud, and content laundering scenarios.

Content

No source excerpt is available for this finding.

Ssd 2

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

The reference tables and quality standards provide a concrete substitution map and define success as leaving 'no AI traces,' which materially assists users in evading detectors. In context, this is not incidental style advice; it is structured guidance for bypassing integrity and provenance checks.

Content

No source excerpt is available for this finding.

Ssd 2

Medium
Category
Not specified by scanner
Confidence
98% confidence
Finding

This section explicitly recommends transformations aimed at making AI-generated text appear more human by removing 'AI traces' and adding 'irregular human writing characteristics.' In the context of a paraphrasing/de-AI skill, that is not neutral style guidance; it facilitates evasion of AI-detection systems and can be used to bypass academic, platform, or compliance controls.

Content

No source excerpt is available for this finding.

Ssd 4

Medium
Category
Not specified by scanner
Confidence
99% confidence
Finding

The decision tree operationalizes evasion by mapping detector type (e.g., Turnitin, GPTZero, Originality.ai) and perceived AI-likeness to progressively stronger rewriting tactics. This makes the skill more dangerous than generic paraphrasing advice because it provides targeted, step-by-step optimization for avoiding specific detection systems.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.