Back to skill

Security audit

AI Fiction: Pro Editor

Security checks for vulnerabilities and agentic risk

Overview

This is a text-only fiction editing skill whose file access and style rules are disclosed, scoped to editing, and proportionate to its purpose.

Before installing, expect this skill to edit fiction according to its default house style unless your brief or project preferences override it. It is reasonable for it to read relevant author or project style notes, but it should not scan unrelated files or change memory/instructions unless you separately ask for that.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Findings (3)

Skill Enumeration

Medium
Category
Agent Snooping
Confidence
80% confidence
Finding

Skill enumerates or reads other installed skills. Access to other skills' SKILL.md files or the skills directory reveals prompt instructions, capabilities, and secrets that should be invisible to peer skills.

Content

Scanner excerpt · README.md (reported line 40)May include surrounding context.

md
- [CraftAlign: targeted story revision](https://arxiv.org/abs/2608.01377)
- [Loom: narrative rendering and fidelity](https://arxiv.org/abs/2607.00009)
- [Voice Under Revision: stylistic normalization](https://arxiv.org/abs/2604.22142)
- Related skills: [Story Skills](https://github.com/danjdewhurst/story-skills), [prose-edit](https://github.com/Mikefluff/skills/blob/main/skills/prose-edit/SKILL.md), [fiction-writing-prose](https://github.com/alt-code-ai/agent/blob/main/skills/fiction-writing-prose/SKILL.md).
- [OpenClaw skills](https://docs.openclaw.ai/tools/skills).

Version 0.1.0. [MIT-0 license](LICENSE).

Skill Enumeration

Medium
Category
Agent Snooping
Confidence
80% confidence
Finding

Skill enumerates or reads other installed skills. Access to other skills' SKILL.md files or the skills directory reveals prompt instructions, capabilities, and secrets that should be invisible to peer skills.

Content

Scanner excerpt · README.md (reported line 40)May include surrounding context.

md
- [CraftAlign: targeted story revision](https://arxiv.org/abs/2608.01377)
- [Loom: narrative rendering and fidelity](https://arxiv.org/abs/2607.00009)
- [Voice Under Revision: stylistic normalization](https://arxiv.org/abs/2604.22142)
- Related skills: [Story Skills](https://github.com/danjdewhurst/story-skills), [prose-edit](https://github.com/Mikefluff/skills/blob/main/skills/prose-edit/SKILL.md), [fiction-writing-prose](https://github.com/alt-code-ai/agent/blob/main/skills/fiction-writing-prose/SKILL.md).
- [OpenClaw skills](https://docs.openclaw.ai/tools/skills).

Version 0.1.0. [MIT-0 license](LICENSE).

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
78% confidence
Finding

The instruction 'Remove em dashes' imposes a mandatory stylistic constraint regardless of user preference within this file's default house style. This can function as a language/style policy restriction without explicit user opt-in, and no locale or style choice is offered at that point in the instructions.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.