Back to skill

Security audit

Mp Grill Me

Security checks for vulnerabilities and agentic risk

Overview

This is a small planning-review skill with no executable code, persistence, credential handling, or hidden data movement.

Install if you want an intensive plan or design reviewer. Be aware it may ask many follow-up questions and may read relevant project files to answer them, so use it in workspaces where that behavior is acceptable.

Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (2)

Vague Triggers

Medium
Confidence
90% confidence
Finding
The trigger language is very broad and overlaps with common requests for plan discussion, design review, and pressure testing. That can cause the skill to activate unexpectedly in situations where the user did not intend a relentless interrogation-style workflow, increasing the chance of confusing behavior, over-collection of user context, or inappropriate codebase exploration.

Natural-Language Policy Violations

Medium
Confidence
76% confidence
Finding
The description mixes English and Chinese without stating language-selection behavior or a locale-specific scope. This can lead to ambiguous triggering, misunderstandings about who the skill is for, and accidental activation for users who match only part of the multilingual phrasing.

Static analysis

No suspicious patterns detected.