Back to skill

Security audit

Storytelling And Narrative

Security checks for vulnerabilities and agentic risk

Overview

This is a disclosed writing-support skill for shaping real brand stories, with no executable code, hidden install behavior, persistence, or credential handling found.

Installers should understand that this skill may read brand voice, profile, testimonial, UGC, and audience-research context to build narrative structure. Review outputs before publishing through downstream tools, especially where customer stories or testimonials require truth and consent.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (4)

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

The trigger example 'Help me turn this flat update into a story' is broad, natural language that could match many ordinary user requests, causing the skill to activate when the user did not specifically intend this narrative-structuring behavior. In an agent ecosystem, over-broad activation can misroute tasks, pull in the wrong dependencies, or override more appropriate skills, creating reliability and policy-boundary issues even without obviously malicious content.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
89% confidence
Finding

The invocation example 'Write a story-driven post for us' is ambiguous because it requests final content generation rather than clearly scoping this skill's intended role as narrative-structure preparation before handing off to format-specific writers. That ambiguity increases the chance of incorrect activation and privilege creep across adjacent skills, especially where multiple writing skills have overlapping capabilities.

Content

No source excerpt is available for this finding.

Vague Triggers

Low
Category
Not specified by scanner
Confidence
85% confidence
Finding

The phrase 'This post feels flat -- how do I make it land?' is a very general content-improvement request that could apply to nearly any writing assistant, not just a storytelling specialist. This makes unintended matching more likely, though the security impact is limited because the skill is content-focused and includes guardrails against fabrication.

Content

No source excerpt is available for this finding.

Vague Triggers

Low
Category
Not specified by scanner
Confidence
82% confidence
Finding

The cross-platform request 'How do I tell this story across platforms and over time?' is broad enough to overlap with campaign planning, content calendar, and format adaptation skills, which can blur execution boundaries. While not dangerous in the classic exploit sense, this can cause skill confusion and inappropriate chaining across sibling agents.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.