Back to skill

Security audit

ere

Security checks for vulnerabilities and agentic risk

Overview

This is a local writing-refinement skill with one factual-drift documentation issue, but no hidden credential, network, persistence, or destructive behavior.

Review refined output against the original before publishing, especially for factual claims. For private or sensitive text, avoid the documented /tmp example filenames and use a private working directory for analysis files.

Vulnerability Patterns
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (1)

Intent-Code Divergence

Medium
Confidence
96% confidence
Finding
The example output violates the skill's own preservation guarantees by introducing unsupported details and omitting source facts, which can normalize factual drift in downstream use. In a refinement skill marketed as preserving entities, numbers, dates, and quotes, contradictory examples are dangerous because users and agents may trust outputs that subtly rewrite meaning.

Static analysis

No suspicious patterns detected.