Back to skill

Security audit

qy-123

Security checks for vulnerabilities and agentic risk

Overview

This is a markdown-only coding guidance skill with broad but disclosed activation and no code execution or data access.

Install this if you want strict coding-style guardrails applied across most development tasks. Review whether its broad fail-fast and testing rules fit your team’s workflow, but the artifact does not show hidden execution, data access, or persistence.

Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (1)

Vague Triggers

High
Confidence
94% confidence
Finding
The skill is configured as mandatory and effectively always-on for nearly all code-writing and code-modification tasks, which gives it persistent influence over a broad set of agent behaviors. Even though the content appears aimed at coding quality, such broad activation increases blast radius: any flawed, conflicting, or adversarial instruction in the skill could systematically affect many unrelated tasks and override more context-appropriate guidance.

Static analysis

No suspicious patterns detected.