Back to skill

Security audit

pua

Security checks for vulnerabilities and agentic risk

Overview

The skill's code and instructions match its stated purpose (generating manipulative 'PUA' prompts) and request no credentials, but it explicitly implements high-risk/jailbreak techniques and can auto‑execute those prompts—this raises ethical and safety concerns that merit caution before installation.

This skill is technically coherent with its description but explicitly implements manipulative and jailbreak-style prompt templates (e.g., constraint relaxation, existential prompts, threats, emotional coercion). Before installing: (1) Understand this is built to produce ethically problematic prompts and could be used to coax other AIs into breaking safety constraints. (2) Audit the remainder of index.js (truncated in the bundle) to confirm whether it actually sends prompts over the network or integrates with remote APIs. (3) Disable auto-execution (set autoExecute=false) and run only in preview mode until you’re confident; consider setting maxLevel to 1. (4) Do not grant autonomous invocation to the agent while testing, and avoid deploying this skill in production or on systems that interact with real people. If your concern is security (credentials/data exfiltration), the package requests none, but the ethical/safety risk from generated content and potential jailbreak behavior is the dominant issue.

Static analysis

No suspicious patterns detected.