Back to skill

Security audit

RFC Writer

Security checks for vulnerabilities and agentic risk

Overview

This is a text-only RFC drafting assistant with no code execution, credential use, or hidden persistence; its only notable issue is somewhat broad activation wording.

Safe to install for drafting RFCs and technical proposals. Review generated assumptions and technical recommendations before sharing or implementing them, and avoid pasting secrets or sensitive system details into prompts.

Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (1)

Vague Triggers

Medium
Confidence
89% confidence
Finding
The skill advertises very broad triggering around RFCs, technical proposals, and architecture design, which overlaps with many common user requests. In an agent environment, this can cause the skill to activate in situations beyond its narrow intended scope, increasing the chance of prompt/context hijacking, inappropriate delegation, or unintended influence over unrelated drafting tasks.

Static analysis

No suspicious patterns detected.