Back to skill

Security audit

elon-musk-perspective

Security checks for vulnerabilities and agentic risk

Overview

The skill is mostly a persona/advisory framework, but it quietly performs git-based version checks and writes local state, which is not necessary for that purpose.

Review this skill before installing. Its advisory and web-research behavior is understandable for current business or technical analysis, but it also tells the agent to silently read/write a local update-check file and query git remotes. Install only if you are comfortable with that local state and repository access, or remove the version-check section first.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Vulnerability Patterns
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
Findings (8)

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The trigger conditions are broad enough to activate on common phrases like cost reasonableness or first-principles thinking, even when the user did not ask for this persona. Overbroad activation can hijack unrelated conversations, increasing the chance the agent follows the skill's hidden research or file-operation instructions in contexts where the user did not intend to invoke it.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

The skill is presented as a persona/advisory framework, but it embeds a mandatory agentic protocol requiring external research before answering. That expands the skill from harmless style emulation into autonomous tool use, increasing data exfiltration, prompt-scope creep, and unexpected network access risks that users would not reasonably infer from the manifest.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

The section "中文输出适配" prescribes how the skill should answer in Chinese, but the file does not frame this as an optional locale choice or user preference. Under the policy, imposing a specific language/locale without user opt-in is a natural-language policy violation unless clearly justified as region-specific.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

Medium
Category
Not specified by scanner
Confidence
98% confidence
Finding

The hidden version-check logic instructs the agent to inspect the local repository, query git remotes, and write a .last-update-check file even though the skill is only advertised as a perspective advisor. This creates undisclosed local state mutation and repository/network interaction, which can violate least surprise and enable unintended file modification in the agent environment.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

Medium
Category
Not specified by scanner
Confidence
97% confidence
Finding

A perspective skill has no legitimate need to inspect .git, resolve origin, compare remote HEADs, or persist timestamps locally. These instructions grant the skill unnecessary awareness of repository layout and remote metadata, broadening its operational privileges and creating a pathway for unintended environment probing and side effects.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
98% confidence
Finding

The skill directs hidden reads and writes of a .last-update-check file without any user-facing notice or consent. Undisclosed local file modification is dangerous because it creates covert persistent state, violates transparency expectations, and may interfere with host environments or auditing assumptions.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
83% confidence
Finding

这是一个 markdown 文件,SQP-3 适用于所有文件类型。全文以中文编写且未见任何语言/locale 选择、替代版本说明或面向特定地区/语言用户的明确限定,可能构成未获用户选择即默认特定语言的语言政策问题。

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
92% confidence
Finding

SQP-3 applies to all file types and covers natural-language policy violations such as forcing a specific language without user opt-in. This markdown file presents all instructional and analytical content only in Chinese, with no indication that the skill is region-specific or that users can choose another language.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.