Back to skill

Security audit

Islamic Knowledge Mastery

Security checks for vulnerabilities and agentic risk

Overview

This is a text-only Islamic study skill focused on source verification and teaching, with no artifact-backed signs of unsafe commands, exfiltration, or hidden privilege use.

Install this as a religious-study helper, not as an unquestioned authority. Ask it to answer in your preferred language, require exact citations for Quran and hadith claims, and be aware that memorization tracking may involve retaining study progress if your agent environment supports memory.

Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Findings (1)

Natural-Language Policy Violations

Medium
Confidence
94% confidence
Finding
The skill switches into Indonesian-only instruction flow ('Kamu adalah...', 'Tugasmu...') without offering a user-language choice, which can reduce transparency and user control. In a religious guidance skill, forcing a language may cause misunderstanding of sourcing, nuance, or safety disclaimers if the user is not fluent.

Static analysis

No suspicious patterns detected.