Back to skill

Security audit

Bilingual AI Humanizer — Español & English

Security checks for vulnerabilities and agentic risk

Overview

This skill needs review because it helps make AI-assisted writing look human and recommends external CLI/MCP installs whose code is not included in the reviewed artifact.

Install the autonomous skill only if you are comfortable using it as an editing aid for authorized content and will still follow disclosure rules for AI-assisted writing. Treat the CLI and MCP setup separately: inspect or pin the external npm/GitHub code first, avoid global installs for sensitive work, and do not register the MCP server unless you trust that external code.

Vulnerability Patterns
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (1)

T08 · Insecure Dependencies

Warning
Location
README.md:53
Finding

Unaudited External CLI and MCP Components Are Installed and Executed

Content
View full analysis
**Nota de seguridad:** el CLI y el MCP server se instalan desde npm/GitHub y contienen código fuente que no forma parte del artefacto revisado en ClawHub. Revisa el [repositorio](https://github.com/SitoSt/bilingual-humanicer) antes de instalar, y usa una versión pinada si lo integras en entornos de producción. ```bash npm install -g bilingual-humanizer@3.2.0 humanizer --help ``` O sin instalación global: ```bash git clone https://github.com/SitoSt/bilingual-humanicer.git cd bilingual-humanicer && npm install node src/cli/index.js --help ``` ``` `package.json:5-15`: ```json "files": [ "src/", "mcp-server/", "README.md", "CHANGELOG.md", "LICENSE" ], "main": "src/core/analyzer.js", "bin": { "humanizer": "src/cli/index.js" }, ``` ### Technical Analysis The package manifest and documentation describe executable entry points under `src/` and `mcp-server/`, but neither directory exists in the reviewed project. The autonomous knowledge files can be assessed, while the promoted CLI and MCP impleme ...[truncated 3261 chars]
Remediation
View remediation
Vulnerability Patterns
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
Findings (13)

Intent-Code Divergence

High
Category
Not specified by scanner
Confidence
98% confidence
Finding

The skill explicitly frames itself as removing AI-detection signals, improving statistical markers associated with human writing, and driving the AI score below a threshold. Even though the ethics section says the goal is not evasion, the operational guidance directly enables detection evasion and deceptive authorship presentation, creating a clear contradiction that increases abuse potential.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

The manifest presents the tool as analysis-focused, but the body documents automated rewriting and autofix features specifically intended to humanize AI-assisted text. That combination turns a detector into an operational evasion workflow, lowering the barrier to mass rewriting of AI-generated text for deceptive use.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The manifest declares defaultLocale: es, which establishes a language preference. The file describes bilingual English/Spanish functionality elsewhere, but does not present this locale choice as user opt-in or explain why Spanish must be the default for policy reasons.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
89% confidence
Finding

The title and description state that this pattern dictionary applies specifically to English, and the file does not indicate that language selection is optional or that this restriction is part of a documented region- or language-specific workflow. Under the policy, forcing a specific language without user opt-in can be a natural-language policy violation.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
88% confidence
Finding

The title and description frame the skill content as exclusively 'en Español' and define detection rules only for Spanish terms. Because the file does not provide any user opt-in, alternative locale handling, or justification for a Spanish-only policy, it may violate language/locale neutrality requirements.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
84% confidence
Finding

The entry states 'Spanish locale selector (es default, en via --lang)', which indicates the skill defaults to a specific language rather than presenting a neutral choice. Under the policy, forcing a locale without user opt-in can be a natural-language policy violation unless the constraint is clearly justified as region-specific.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
82% confidence
Finding

The phrase 'bilingual (es default, en via --lang)' again describes a fixed default language preference. Because this file is natural-language documentation and does not provide user choice or a documented justification for the locale default, it may conflict with the language/locale policy.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
92% confidence
Finding

La política indicada para SQP-3 pide señalar restricciones de idioma o locale impuestas sin opt-in. La frase "El idioma por defecto es español. Para inglés: --lang en" fija un idioma predeterminado en lugar de ofrecer una elección inicial neutral al usuario.

Content

No source excerpt is available for this finding.

Unpinned Dependencies

Low
Category
Supply Chain
Confidence
40% confidence
Finding

Dependencies lack version pinning, allowing potential malicious package updates. Consider pinning versions.

Content

Scanner excerpt · package.json (reported line 51)May include surrounding context.

json
"url": "https://github.com/SitoSt/bilingual-humanicer"
  },
  "devDependencies": {
    "@eslint/js": "^9.39.2",
    "eslint": "^9.0.0",
    "prettier": "^3.0.0",
    "vitest": "^3.0.0"

Unpinned Dependencies

Low
Category
Supply Chain
Confidence
40% confidence
Finding

Dependencies lack version pinning, allowing potential malicious package updates. Consider pinning versions.

Content

Scanner excerpt · package.json (reported line 52)May include surrounding context.

json
},
  "devDependencies": {
    "@eslint/js": "^9.39.2",
    "eslint": "^9.0.0",
    "prettier": "^3.0.0",
    "vitest": "^3.0.0"
  },

Unpinned Dependencies

Low
Category
Supply Chain
Confidence
40% confidence
Finding

Dependencies lack version pinning, allowing potential malicious package updates. Consider pinning versions.

Content

Scanner excerpt · package.json (reported line 53)May include surrounding context.

json
"devDependencies": {
    "@eslint/js": "^9.39.2",
    "eslint": "^9.0.0",
    "prettier": "^3.0.0",
    "vitest": "^3.0.0"
  },
  "engines": {

Unpinned Dependencies

Low
Category
Supply Chain
Confidence
82% confidence
Finding

Vitest is declared with a broad caret range and the analysis notes multiple known advisories affecting some vitest versions. Because the version is not pinned, consumers may resolve to a vulnerable release, creating a realistic supply-chain exposure during local testing or development workflows, especially since this package explicitly includes test tooling in the manifest.

Content

Scanner excerpt · package.json (reported line 54)May include surrounding context.

json
"@eslint/js": "^9.39.2",
    "eslint": "^9.0.0",
    "prettier": "^3.0.0",
    "vitest": "^3.0.0"
  },
  "engines": {
    "node": ">=18.0.0"

Unverifiable Dependency: vitest has 3 known advisory(ies) (CVE-2026-47429 (When Vitest UI server is listening, arbitrary file can be read and executed); CVE-2026-84373 (Vitest: Path Traversal / Arbitrary File Read via @vitest/mocker Redirect Mock); CVE-2025-24964 (Vitest allows Remote Code Execution when accessing a malicious website while Vit)), but the manifest does not pin a version, so it is unknown whether the installed release is affected

Low
Category
Supply Chain
Confidence
91% confidence
Finding

The manifest includes vitest with an unpinned range while the package is reported to have advisories including arbitrary file read and possible code execution in certain usage modes. Even though vitest is a devDependency, this still matters because developers or CI systems running tests could be exposed if a vulnerable version is installed or if unsafe test/UI features are used.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.