Back to skill

Security audit

Leadership CARE Story Builder

Security checks for vulnerabilities and agentic risk

Overview

This is a leadership-story writing guide with no executable code, hidden data access, or persistence; its optional cross-skill suggestions are disclosed and limited.

Review the optional cross-skill suggestions if you use this in a workspace with those skills installed, but the submitted artifact is a proportionate coaching/writing aid and does not itself run commands, access private data, or install anything.

Vulnerability Patterns
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (1)

Context-Inappropriate Capability

Low
Confidence
83% confidence
Finding
The manifest describes a skill for expanding a CARE leadership story builder with richer coaching guidance, which implies a focused coaching/writing aid. The 'Integration With Other Skills' section adds orchestration behavior by recommending use of other skills for influence strategy and interpersonal analysis, a capability not clearly justified by the stated purpose of richer coaching guidance alone.

Static analysis

No suspicious patterns detected.