Ae1
- Category
- analysis-evasion
- Confidence
- 100% confidence
- Finding
Referenced artifact was not completely inspected
- Content
md Global voice rules: see root `SKILL.md` §Voice rules. Additional skill-specific rules:
Security audit
Security checks for vulnerabilities and agentic risk
This skill is a coherent LinkedIn post drafting and publishing workflow, with the main risk being that users should confirm before anything is posted or scheduled publicly.
Before installing, understand that this skill can help publish or schedule real LinkedIn posts through the configured publishing wrapper after approval. Confirm the exact LinkedIn account, final post text, media, and scheduled time before approving publication.
Referenced artifact was not completely inspected
Global voice rules: see root `SKILL.md` §Voice rules. Additional skill-specific rules:
The skill includes a concrete publishing action to LinkedIn via lib.publish(...) after approval, but it does not require an explicit user-facing confirmation warning that content may be posted or scheduled to a real external account. In an agent setting, ambiguous 'approval' handling can lead to unintended publication, reputational harm, or accidental scheduling to the wrong profile if the user does not clearly understand that an external side effect will occur.
These instructions prescribe rigid stylistic rules such as banning em dashes, curly quotes, and Oxford commas, which are language/locale-dependent writing conventions. Because the file presents them as mandatory requirements rather than optional preferences, it can violate policy against forcing a specific language or locale style without user choice.
No suspicious patterns detected.