Back to skill

Security audit

Justin Ex Clapback Writing Style

Security checks for vulnerabilities and agentic risk

Overview

This is a disclosed creative-writing style skill with no code execution or data access, but users should keep its satire fictional and remove the stray local memory file before publishing.

Install only if you want a fictional satire-writing style. Do not use it to target real people, ongoing disputes, private individuals, or identifiable public figures through hints or nicknames; replace “孙哥” with fully generic labels such as “A先生”. Before redistributing, remove the hidden .workbuddy memory file because it is unrelated local workflow residue.

Vulnerability Patterns
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (5)

Intent-Code Divergence

Medium
Confidence
98% confidence
Finding
The report contains internally contradictory status claims about whether P1/P2 remediation items were already completed or still pending. This undermines the reliability of the audit artifact and can cause maintainers or deployment gates to approve a skill based on fixes that may not actually exist.

Intent-Code Divergence

Medium
Confidence
97% confidence
Finding
The document says the golden-set was already added and integrated, but the closing note states it remains a recommendation pending confirmation. That inconsistency can mislead reviewers into believing external validation exists when it may not, weakening assurance around output quality and policy compliance.

Intent-Code Divergence

Medium
Confidence
97% confidence
Finding
The report asserts orphaned meta files were already resolved, yet later frames that work as merely recommended. Such contradictory statements can hide packaging or review gaps and reduce trust in the audit process and downstream deployment decisions.

Description-Behavior Mismatch

Medium
Confidence
94% confidence
Finding
The style guide allows a semi-specific named reference ('孙哥') under some conditions, which weakens the otherwise strict rule against real names. In a writing skill designed to generate social-media-style clapback content about exes, even partial or nickname-based identifiers can facilitate targeting, defamation, or re-identification of real individuals.

Missing User Warnings

Medium
Confidence
91% confidence
Finding
The runtime explicitly optimizes for producing '前任回怼' content that is emotionally barbed, persona-targeted, and socially publishable, but it contains no runtime safeguard against harassment, bullying, or reputational targeting. Even though it bans real names and direct copying, the style instructions still encourage hostile interpersonal content that can be adapted to identifiable private individuals through contextual details and implied references.

Static analysis

No suspicious patterns detected.