Back to skill

Security audit

Tech Debate

Security checks for vulnerabilities and agentic risk

Overview

This is a markdown-only skill that structures technical debates and does not request file access, commands, credentials, network use, or persistence.

Install this if you want a structured debate assistant for technical decisions. Be aware that it is primarily Chinese-language and may activate on broad debate phrasing; avoid entering sensitive proprietary topics unless you are comfortable having them used in the current agent session.

Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (2)

Vague Triggers

Medium
Confidence
83% confidence
Finding
The trigger examples include very generic everyday phrases such as "tech debate" and broad natural-language variants, which can cause the skill to activate when the user did not explicitly intend to enter a multi-agent debate workflow. Unintended activation can disrupt normal assistant behavior, pull the conversation into a structured role-play flow, and create prompt-routing confusion that may be abused to derail user sessions.

Natural-Language Policy Violations

Medium
Confidence
75% confidence
Finding
The skill description and interaction examples are Chinese-only and do not indicate that the skill will adapt to the user's language, which can force or strongly bias interaction into a language the user did not choose. This is primarily a safety and usability issue: users may misunderstand the workflow, intervention options, or outputs, leading to incorrect operation or reduced transparency.

Static analysis

No suspicious patterns detected.