Back to skill

Security audit

humanize-mba-text-skill

Security checks for vulnerabilities and agentic risk

Overview

The skill does not look like malware, but it is explicitly built to reduce AI-detection and plagiarism-check signals in MBA thesis text.

Review before installing. Use only for transparent editing, formatting, and clarity work that complies with school or publisher rules. Do not use it to hide AI authorship, bypass AI detectors, or lower plagiarism/similarity scores for submitted academic work; preview any applied changes and verify all citations, data, and meaning yourself.

Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
Findings (38)

Tp4

High
Category
MCP Tool Poisoning
Confidence
89% confidence
Finding
The declared purpose presents the skill as a benign rewriting aid, but the document makes clear its primary behavior is detection, scoring, reporting, and AI-trace reduction workflows aimed at making text appear human-written. This mismatch can mislead users, reviewers, or policy controls about what the skill actually does and can conceal an evasion-oriented function in an academic context.

Description-Behavior Mismatch

Medium
Confidence
84% confidence
Finding
The manifest markets a humanization/rewriting capability, yet the referenced section explicitly says the skill's main path is detection rather than rewriting. This inconsistency increases operational risk because downstream systems and users may invoke the skill under false assumptions, especially where policy distinguishes editing from evasion tooling.

Intent-Code Divergence

Medium
Confidence
77% confidence
Finding
The document says it does not perform deep academic content review, yet it describes semantic evidence-chain checks and source-related analysis that go beyond mere formatting or surface style. This can cause users to overtrust or misunderstand the scope of analysis, leading to inappropriate use or weak governance around academic-review features.

Context-Inappropriate Capability

High
Confidence
99% confidence
Finding
This reference data directly instructs the skill to reduce AI detection rates and lower plagiarism overlap, which goes beyond benign style editing and facilitates evasion of academic integrity controls. In the context of an MBA thesis humanization skill, these goals materially increase the likelihood that users can disguise AI-generated or derivative academic work as original human authorship.

Description-Behavior Mismatch

High
Confidence
99% confidence
Finding
The file’s stated strategy is explicitly about reducing plagiarism/checker similarity scores, not merely improving writing naturalness. It provides operational guidance for preserving meaning while changing wording and structure to avoid academic-detection systems, which materially increases the likelihood of academic-integrity abuse.

Context-Inappropriate Capability

High
Confidence
98% confidence
Finding
The later sections operationalize similarity-evasion with checklists, principles, and a recommended workflow for validating reduced detection risk. That capability is not justified by the manifest’s benign framing and makes the skill more dangerous because it can be directly used to conceal copied or improperly reused academic material.

Description-Behavior Mismatch

High
Confidence
99% confidence
Finding
This file implements a full AI-text detection, scoring, and report-generation pipeline, then produces concrete modification plans to reduce the detected AI score and increase a 'humanization score.' In the context of a skill advertised as removing AI traces from MBA thesis text, this is functionally an evasion workflow that helps users conceal AI-generated academic writing rather than merely edit for clarity.

Intent-Code Divergence

Medium
Confidence
92% confidence
Finding
The module docstring explicitly describes the tool as a multi-method AI-feature detector, which directly conflicts with the claimed purpose of benign humanization. That mismatch is dangerous because it indicates the skill is designed around detection-and-evasion mechanics, obscuring its real behavior from reviewers and making misuse for academic deception easier.

Intent-Code Divergence

Medium
Confidence
95% confidence
Finding
The CLI description and output flow operationalize the detector by reading text, computing AI probability, generating a modification plan, and printing prioritized fixes and MBA-specific advice. This turns the module into an actionable concealment tool, lowering the barrier for users to iteratively rewrite content until it better avoids AI detection.

Vague Triggers

Medium
Confidence
78% confidence
Finding
The trigger phrases are broad enough that normal requests like improving style or making text sound more natural could activate a skill explicitly designed to remove AI traces. In context, that increases the chance of unintended assistance with evading AI-detection or academic-integrity controls, especially when users paste assignment or thesis text without understanding the skill's purpose.

Missing User Warnings

Medium
Confidence
84% confidence
Finding
The README advertises automatic repair/application of modifications without a strong warning that user content may be changed, which can lead to silent or unexpected alteration of academic text. In an academic-writing context, such changes can affect meaning, citations, claims, and evidentiary accuracy, creating integrity and data-loss risks if users assume the operation is advisory only.

Vague Triggers

Medium
Confidence
82% confidence
Finding
The trigger phrases are broad enough that ordinary editing requests such as 'help me remove AI writing traces' can invoke an evasion-oriented skill without clear user intent confirmation. In agent environments, ambiguous activation can cause unsafe workflow routing and accidental assistance with academic-integrity circumvention.

Vague Triggers

Medium
Confidence
89% confidence
Finding
The trigger phrases are broad enough to activate on ordinary editing requests, increasing the chance that the skill will intervene when the user did not explicitly request AI-authorship concealment behavior. In this skill’s context, that can steer benign proofreading into deceptive academic rewriting intended to evade AI-detection or authorship scrutiny.

Vague Triggers

Medium
Confidence
90% confidence
Finding
The trigger phrases are broad enough to activate on ordinary editing requests, increasing the chance the skill is invoked without clear user intent for this specialized behavior. In context, that behavior is specifically oriented toward removing AI-writing traces from academic text, which can cause the assistant to drift into deceptive rewriting when a user merely asks for polishing.

Missing User Warnings

Medium
Confidence
95% confidence
Finding
The file explicitly teaches users how to reduce AI-detection rates in MBA thesis writing and frames success in terms of evading detector thresholds, yet it provides no guardrails about academic integrity, disclosure, or institutional policy compliance. In this skill context, that omission materially increases misuse risk because the stated purpose is to make AI-generated academic text appear human-written, which can facilitate deception, policy evasion, and academic fraud.

Vague Triggers

Medium
Confidence
83% confidence
Finding
The metadata describes a broad 'MBA thesis humanization' purpose without clear guardrails limiting use to legitimate proofreading or disclosure-compliant editing. That ambiguity is dangerous here because the surrounding file already includes evasion-oriented goals, making it easy for downstream components to apply these strategies in improper academic contexts.

Ssd 2

Medium
Confidence
95% confidence
Finding
The README explicitly promotes removing AI-writing traces and lowering AI-detection signals, which is an evasion use case rather than neutral editing assistance. In the academic context of MBA theses, this can facilitate circumvention of institutional detection, misconduct review, or authenticity checks, making the skill materially more dangerous than a generic style improver.

Ssd 2

Medium
Confidence
94% confidence
Finding
Natural-language references to lowering AI detection rates still communicate clear evasion intent, even without explicit attack terminology. Because the skill is specialized for academic writing, these claims support misuse for disguise of AI-generated coursework and increase the likelihood that the system will be used to defeat compliance or integrity mechanisms.

Ssd 2

Medium
Confidence
96% confidence
Finding
The trigger examples directly instruct the model to remove AI-writing traces from pasted text, operationalizing evasion as a first-class workflow. This lowers misuse friction and makes the dangerous behavior easy to invoke, particularly for students attempting to conceal AI-generated thesis content from academic scrutiny.

Ssd 2

Medium
Confidence
93% confidence
Finding
The risk-based strategy explicitly recommends deeper rewriting when AI-generated probability is high, which is effectively an optimization loop for detector evasion. In an academic-thesis skill, this turns the tool from passive analysis into active concealment guidance, increasing the risk of systematic abuse against academic-integrity controls.

Ssd 2

Medium
Confidence
97% confidence
Finding
The README explicitly frames the skill as removing detectable signs of AI authorship from MBA theses, which is an evasion objective rather than neutral writing support. In an academic context, that can facilitate deception, undermine provenance checks, and help users misrepresent AI-assisted work as human-authored.

Ssd 2

High
Confidence
98% confidence
Finding
The optimization strategy explicitly includes reducing AI-detection and plagiarism signals, showing deliberate support for bypassing integrity and screening systems. This materially increases misuse potential because it operationalizes evasion through structured guidance rather than incidental editing help.

Ssd 4

High
Confidence
97% confidence
Finding
The documented workflow chains detection, rewrite planning, and automatic modification specifically to make text less machine-detectable. That end-to-end process lowers the effort required to evade AI-origin screening and converts a risky objective into a repeatable operational capability.

Ssd 2

High
Confidence
98% confidence
Finding
The guidance to perform 'deep rewriting' and remove all AI-characteristic vocabulary based on detector scores is explicit instruction for defeating content-origin checks. In the thesis context, this directly supports academic misconduct by helping users conceal AI assistance and present work as more authentically human-authored.

Ssd 4

Medium
Confidence
95% confidence
Finding
The README frames AI-trace detection and removal as a normal workflow for academic writing, which normalizes concealment of AI assistance in a thesis setting. In an academic-integrity context, this materially increases the risk that users will use the skill to misrepresent authorship and bypass institutional review mechanisms.

Static analysis

No suspicious patterns detected.