Back to skill

Security audit

elite-writing-skill

Security checks for vulnerabilities and agentic risk

Overview

This is a markdown-only writing assistant skill with disclosed writing and copywriting behavior, no executable requirements, and no hidden data access or persistence beyond installation.

Installers should expect this skill to influence a wide range of writing requests, especially persuasive and marketing copy. Review generated claims, urgency, testimonials, citations, and platform disclosure requirements before publishing.

Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (3)

Vague Triggers

Medium
Confidence
89% confidence
Finding
The README encourages users to ask the agent to write 'APA SAJA' and describes automatic framework selection without clear boundaries, exclusions, or activation constraints. In an agentic environment, overly broad invocation scope can cause the skill to activate for inappropriate requests, override more suitable safeguards or domain-specific skills, and increase the chance of generating unsafe persuasive, deceptive, or policy-sensitive content.

Vague Triggers

Medium
Confidence
94% confidence
Finding
The activation description uses very broad trigger phrases like 'tulis', 'buat copy', 'draft artikel', and 'perbaiki tulisan', which can cause the skill to activate in many ordinary conversations beyond the user's clear intent. Over-broad auto-invocation increases the chance that persuasive-writing behaviors and referenced frameworks are injected into unrelated tasks, creating prompt-scope creep and reducing user control over agent behavior.

Natural-Language Policy Violations

Medium
Confidence
89% confidence
Finding
The description is written as if the skill should operate in Indonesian without offering user choice or documenting a locale restriction, which can override user language expectations and cause unintended language switching. While not a direct security exploit, forced locale behavior can degrade instruction fidelity, confuse users, and make downstream review or safety validation harder in multilingual environments.

Static analysis

No suspicious patterns detected.