Back to skill

Security audit

Detector AI

Security checks for vulnerabilities and agentic risk

Overview

This skill is a local AI-text detector whose behavior matches its stated purpose and shows no evidence of hidden access, network transfer, persistence, or destructive actions.

Install only if you are comfortable providing text to a local detector for analysis. Avoid submitting secrets, regulated personal data, or confidential documents unless that is intended, and treat the AI-detection score as advisory rather than proof.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
Findings (4)

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
86% confidence
Finding

The skill advertises script-based analysis capabilities but does not declare an explicit tool scope or permissions boundary. That creates ambiguity about what file access is intended and can lead to broader-than-expected access being granted or assumed by the agent runtime, especially since user-provided text analysis may involve reading local inputs or reference files.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
84% confidence
Finding

The invocation guidance lists several trigger phrases, but it also frames activation as any time users want to check whether text was written by AI, without clear scope boundaries or exclusion conditions. Phrases like "check if AI wrote this" and the broad use-case wording could match ordinary conversational requests, increasing the chance of unintended invocation.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
89% confidence
Finding

The skill explicitly asks users to paste text for analysis but provides no warning about privacy, sensitive data, or handling of proprietary content. Users may submit personal, confidential, academic, legal, or business material under the assumption it is safe to process, increasing the risk of inadvertent exposure or inappropriate retention.

Content

No source excerpt is available for this finding.

Missing User Warnings

Low
Category
Not specified by scanner
Confidence
84% confidence
Finding

This code reads arbitrary text from a file and processes it for AI-detection, but provides no disclosure when ingesting potentially sensitive user content from disk. For code files, safety-relevant data handling should have some visible user disclosure such as a prompt, log message, or explanatory comment/docstring near the operation.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.