Back to skill

Security audit

Results Claim & Hedging Checker

Security checks for vulnerabilities and agentic risk

Overview

This is a document-review skill for academic Results sections, with no install-time code or hidden system access, though its scope and output-language documentation should be clearer.

Before installing, treat this as a focused claim-strength and hedging reviewer, not a full statistical reporting or analysis validator. Users working in English should also be aware that the skill requires Chinese-style scoring labels and headings unless revised.

Vulnerability Patterns
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (5)

Description-Behavior Mismatch

Medium
Confidence
92% confidence
Finding
The README presents a capability mismatch: earlier it says the skill checks statistical reporting completeness, but the scope boundary later says statistical reporting format and completeness are out of scope and delegated elsewhere. This can cause users or orchestrating systems to rely on this skill for checks it will not perform, creating a coverage gap where important statistical-reporting issues may be missed.

Description-Behavior Mismatch

Medium
Confidence
95% confidence
Finding
The manifest advertises statistical reporting completeness checks, but the body explicitly excludes statistical reporting format/completeness from scope. This creates a capability mismatch that can misroute users and downstream orchestration into relying on this skill for checks it will not perform, producing silent coverage gaps in academic-review workflows.

Intent-Code Divergence

Low
Confidence
89% confidence
Finding
The skill documentation says it diagnoses five problem types, while the manifest describes an additional statistical-reporting-completeness function. This inconsistency is a specification integrity issue: users or calling agents may expect a sixth review dimension that is not actually delivered.

Natural-Language Policy Violations

Medium
Confidence
87% confidence
Finding
The skill accepts English or Chinese input but mandates Chinese-only scoring phrasing and output conventions without user opt-in. This can cause policy/quality failures in multi-agent systems, user confusion, and incorrect formatting relative to the requested language, especially when integrated into English-language academic editing pipelines.

Natural-Language Policy Violations

Medium
Confidence
90% confidence
Finding
The skill claims optimization for English academic writing while also imposing mandatory Chinese output structure, creating an undocumented and conflicting language constraint. In orchestrated environments this can degrade reliability, break downstream consumers expecting English, and undermine user trust through inconsistent behavior.

Static analysis

No suspicious patterns detected.