Back to skill

Security audit

Daily English Speaking Practice

Security checks for vulnerabilities and agentic risk

Overview

This is a simple English-speaking practice skill with no code, persistence, credential use, or data access beyond the conversation itself.

Before installing, note that this skill may activate on broad Chinese requests about practicing spoken English. That is the main practical consideration; otherwise the inspected artifact is a conversational tutor with no code execution or sensitive access.

Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (1)

Vague Triggers

Medium
Confidence
94% confidence
Finding
The trigger list includes very generic phrases such as "练口语", "口语练习", and "英语对话练习" that closely match common user requests. This can cause the skill to activate unintentionally and intercept broad conversational traffic, expanding its reach beyond clearly consented invocation.

Static analysis

No suspicious patterns detected.