Back to skill

Security audit

Humanize Text

Security checks for vulnerabilities and agentic risk

Overview

This skill is a straightforward text-cleanup helper that can modify user-selected files, with no evidence of hidden network access, persistence, credential use, or unrelated behavior.

Install this if you want an agent to clean up AI-like writing patterns. Use care on important documents because the skill may edit files in place when asked to process files; ask for a diff or approval step before overwriting valuable content.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
Findings (3)

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
92% confidence
Finding

The skill explicitly instructs the agent to read a file, transform it, and write it back, but it declares no tool scope or allowed-tools restrictions. That mismatch can let a broadly invoked editing skill perform file modifications without clear capability boundaries, increasing the chance of unintended or over-broad file writes.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
90% confidence
Finding

The trigger phrases are very broad and overlap with normal editing requests like 'make this sound human' or 'clean up AI writing.' This can cause the skill to activate in contexts the user did not intend, which is more risky here because the skill also describes file-modifying behavior.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The skill says that for files it should read the file, apply transformations, and write it back, but it does not present a prominent warning that user files may be modified. Without an explicit safety check, users may not realize the skill can overwrite content, especially since its primary framing is simple text cleanup.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.