Back to skill

Security audit

Cold Case Investigator

Security checks for vulnerabilities and agentic risk

Overview

This markdown-only skill performs public-web cold-case research and clearly labels creative speculation, with no hidden install steps, credentials, or background behavior.

Use this for public-source cold-case or true-crime creative research. Expect broad web searches involving names, case details, forums, and media; verify important claims manually, do not treat Track B speculation as fact, and avoid using outputs to accuse, harass, or identify private individuals.

Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
Findings (7)

Intent-Code Divergence

Medium
Confidence
95% confidence
Finding
The skill’s core-principles section promises 'only extract, do not infer,' but later introduces Track B speculation with intuition-based directions. This contradiction can cause downstream agents or users to blur factual evidence and conjecture, especially in sensitive real-crime contexts where unsupported theories may be mistaken for investigative conclusions.

Vague Triggers

Medium
Confidence
89% confidence
Finding
The trigger conditions are broad enough to activate on generic requests like 'help me investigate' or 'find information about X,' increasing the chance the skill hijacks unrelated research tasks. In an agent environment, overbroad auto-triggering can cause inappropriate collection, speculative framing, or unsafe handling of sensitive topics without clear user intent.

Vague Triggers

Medium
Confidence
88% confidence
Finding
The creative-mode triggers are ambiguous and could match routine brainstorming requests, causing the skill to inject true-crime sourcing, speculation, or external-search workflows into benign creative tasks. That creates unnecessary privacy, safety, and reputational risk because users may receive real-case material or conjectural crime framing they did not actually request.

Missing User Warnings

Low
Confidence
85% confidence
Finding
The guidance pushes mandatory multi-language searching and notes benefits, but does not pair that advice with upfront safeguards around mistranslation, cultural nuance, privacy boundaries, or the analyst's actual language ability. In a skill designed for iterative deep investigation of real people and cases, this can lead to incorrect conclusions, overcollection of sensitive personal information, or unsafe reliance on machine translation when handling ambiguous or defamatory material.

Natural-Language Policy Violations

Medium
Confidence
91% confidence
Finding
The document states that cold-case searches 'must' use the case country's official language, removing user choice and pushing the workflow toward broader cross-border collection by default. In this skill's context—deep investigation of unsolved crimes and real individuals—that requirement increases the chance of unintended privacy intrusion, misinterpretation of foreign-language materials, and jurisdictionally sensitive research without confirming necessity or consent.

Natural-Language Policy Violations

Medium
Confidence
95% confidence
Finding
The protocol hard-codes Chinese as the translation target without checking the user's language preference or obtaining opt-in. This can cause unintended language switching, reduce usability, and potentially expose users to misunderstandings in high-stakes investigative or legal contexts where preserving the requested output language matters.

Natural-Language Policy Violations

Medium
Confidence
96% confidence
Finding
The required delivery format mandates Chinese output for every translated segment, removing user choice and forcing a single-language response pattern. In a skill handling multilingual case research, this rigidity can mislead users, interfere with accurate review of source material, and increase the chance of operational errors if the user expected another language or bilingual output.

Static analysis

No suspicious patterns detected.