Back to skill

Security audit

Indirect English Translator

Security checks for vulnerabilities and agentic risk

Overview

This skill is a text-only language helper with no code execution or data access, though its automatic invocation may sometimes interpret messages the user did not explicitly ask to analyze.

Install this if you want help interpreting indirect English and drafting clarifying replies. For sensitive messages, treat its output as a possible reading rather than certainty, and confirm important interpretations directly in writing.

Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (2)

Vague Triggers

Medium
Confidence
92% confidence
Finding
The default prompt and invocation description are broad enough that ordinary user messages containing indirect or polite English could trigger the skill unintentionally. Because the skill rewrites user meaning into a more direct interpretation, unintended activation can distort intent, override user expectations, or introduce unsafe paraphrasing in normal conversations.

Vague Triggers

Medium
Confidence
96% confidence
Finding
Enabling implicit invocation without scope limits means the system may call this skill automatically in ambiguous contexts, even when the user did not request interpretation. In a meaning-transformation skill, this increases the risk of misrepresentation, privacy issues, and unwanted behavioral interference with other tasks.

Static analysis

No suspicious patterns detected.