Back to skill

Security audit

SimInTech Coder

Security checks for vulnerabilities and agentic risk

Overview

This is a Russian-language SimInTech coding helper with no executable code or sensitive access requests.

Install this if you want Russian-language help with SimInTech examples and modeling guidance. Review generated engineering code before using it in real projects, and expect the skill to prefer Russian even if your broader workspace normally uses another language.

Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Findings (1)

Natural-Language Policy Violations

Medium
Confidence
95% confidence
Finding
The skill explicitly instructs the agent to always answer in Russian, regardless of the user's language preference or consent. This can override user expectations and system-level UX policies, causing confusion, reduced accessibility, or mishandling of safety-critical requests if the user cannot reliably understand the response.

Static analysis

No suspicious patterns detected.