Back to skill

Security audit

Science Technology Research Intelligence

Security checks for vulnerabilities and agentic risk

Overview

This is a documentation-only research guidance skill with broad science and technology scope but no hidden execution, credential use, or persistence mechanism.

Install only if you want broad research-assistance behavior. For high-risk domains such as medical, bio/chemistry, cybersecurity, or engineering safety, keep normal platform safety rules and independent expert validation in place.

Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (1)

Vague Triggers

Medium
Confidence
91% confidence
Finding
The usage instruction 'Use when the conditions in the description are met' is too vague to constrain when this skill should be activated. In an agent setting, ambiguous scope can cause over-broad invocation for sensitive scientific, engineering, or research tasks, increasing the chance of misuse, unsafe assistance, or policy bypass through inappropriate delegation to the skill.

Static analysis

No suspicious patterns detected.