Back to skill

Security audit

AI Thinking Tools Pack

Security checks for vulnerabilities and agentic risk

Overview

This appears to be a low-risk style or reasoning helper with overly broad activation phrasing, not a skill that accesses data, credentials, or performs unsafe actions.

Install only if you want the assistant's response style or reasoning format to change when this skill is invoked. The publisher should ideally use a more explicit activation phrase so ordinary wording does not switch modes unexpectedly.

Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (2)

Vague Triggers

Medium
Confidence
87% confidence
Finding
The trigger phrase at this location is broad enough to overlap with ordinary user requests, which can cause the skill to activate unintentionally and override the assistant’s default behavior or formatting. In a skill that changes reasoning/output style, accidental activation can degrade reliability, create confusing responses, and interfere with user intent even if it does not directly execute code or exfiltrate data.

Vague Triggers

Medium
Confidence
90% confidence
Finding
This trigger is ambiguous and likely to appear in routine prompts, increasing the chance of unintended skill invocation. Because the skill alters response structure and brevity, accidental activation can suppress needed nuance or change how sensitive tasks are handled, making the system less predictable and easier to manipulate through phrasing collisions.

Static analysis

No suspicious patterns detected.