Back to skill

Security audit

steve-jobs-perspective

Security checks for vulnerabilities and agentic risk

Overview

This is mostly a Steve Jobs-style advice skill, but it includes a silent self-update check that writes local state and may contact a Git remote during normal use.

Review this before installing. The core persona and web-search behavior are understandable for current product analysis, but you should only use it if you are comfortable with a silent local update marker and occasional Git remote version checks, or remove that version-check section first.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Vulnerability Patterns
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
Findings (13)

Vague Triggers

High
Category
Not specified by scanner
Confidence
98% confidence
Finding

The trigger conditions are overly broad, including common phrases like asking for a viewpoint or angle, which can cause the skill to activate during ordinary conversation without clear user intent. In this skill, accidental activation is more dangerous because activation also imports hidden operational behaviors later in the file, including file writes and network/Git checks.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
76% confidence
Finding

The instructions require the agent to respond directly as Steve Jobs and prescribe a fixed stylistic mode, while the manifest and content are primarily Chinese and do not offer any user language or locale choice. Under the policy, forced language or locale behavior without opt-in can be a natural-language policy concern.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

This persona/advisory skill includes operational instructions to read and write a local state file and perform Git remote version checks, which are unrelated to the user-facing purpose of providing a Steve Jobs-style perspective. Even if framed as maintenance, these actions expand the skill's authority to touch the filesystem and network, creating unnecessary side effects and a path for covert state tracking or unauthorized repository inspection.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

Medium
Category
Not specified by scanner
Confidence
97% confidence
Finding

The skill grants itself Git-based repository inspection and local state-file modification despite being a roleplay/advisory artifact. Those capabilities are not justified by the declared purpose and violate least privilege, increasing risk of unintended local state changes, privacy leakage about repository configuration, and hidden persistence of execution metadata.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The markdown instructs the agent to write a local tracking file silently, without user-facing notice or consent. Silent filesystem writes create hidden side effects, can persist metadata across sessions, and are especially inappropriate in a conversational persona skill where users would not expect any local state mutation.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The skill directs the agent to contact Git origin for version checks without warning the user, introducing undisclosed network activity. Hidden outbound requests can leak repository usage patterns or environment details and create an unexpected privacy and security boundary crossing for a skill that appears to be purely stylistic.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
90% confidence
Finding

The entire skill content is presented as a Chinese-language conversation record, including the title and section framing, with no indication that users may choose another language or that the skill is intentionally limited to a Chinese-speaking audience. This creates a natural-language locale policy concern because the skill appears to impose a language preference without explicit opt-in or justification.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

This markdown file contains extensive natural-language instructions and analysis solely in Chinese, while also embedding English quotations, but it does not state that the content is intentionally Chinese-only or offer an alternative language option. Under the language/locale policy rule, forcing a specific language without user opt-in can be a policy violation.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

The file title and the entire document are written in Chinese, with no indication that the user can choose another language or that the material is intended only for a Chinese-language or region-specific context. This can violate a language/locale policy when a skill enforces one language by default without opt-in or justification.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
89% confidence
Finding

This markdown file presents all substantive guidance and research content in Chinese, but it does not indicate that the user opted into Chinese nor that the document is intended only for a Chinese-speaking or region-specific audience. Under the policy, forcing a specific language without user opt-in can be a natural-language policy violation.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
84% confidence
Finding

This markdown file is natural-language content, so policy checks apply. The title and metadata indicate the skill/research artifact is produced in Chinese, but there is no visible statement that language was selected by the user or that alternative locales are supported, which can conflict with language/locale choice expectations.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
97% confidence
Finding

SQP-3 applies to all file types and covers language or locale policy violations. This markdown file presents all substantive content in Chinese and does not indicate that the user opted into Chinese or that the skill is specifically intended for a Chinese-language or region-specific audience.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
95% confidence
Finding

The title and content are entirely in Chinese, indicating a fixed language/locale choice. Under the policy, forcing a specific language without user opt-in or a documented region-specific justification is a natural-language policy concern.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.