Back to skill

Security audit

Security checks for vulnerabilities and agentic risk

Overview

The skill appears to be a live-stream script generator, but it asks for broad read, write, and command execution authority without a clear need or tight scope.

Review this skill before installing. It may be useful for drafting live-stream scripts, but its declared read, write, and command execution access is broader than the stated purpose, and the documentation does not clearly limit what files, APIs, or commands may be used. Install only if you are comfortable supervising its actions and restricting permissions at the agent/platform level.

Vulnerability Patterns
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
Findings (6)

Description-Behavior Mismatch

Medium
Confidence
93% confidence
Finding
The skill is presented as a live-stream script generator, but the documentation advertises much broader capabilities including file processing, API integration, and command execution. This mismatch expands the apparent trust boundary and can mislead users or agents into granting powerful tools unrelated to the declared purpose, increasing the chance of misuse or prompt-driven abuse.

Context-Inappropriate Capability

High
Confidence
97% confidence
Finding
System command execution is a high-risk capability and is not justified by a skill whose stated role is generating live-stream scripts. If exposed to an agent workflow, this could enable arbitrary local command execution, environment inspection, or chained abuse through prompt injection or operator confusion.

Context-Inappropriate Capability

Medium
Confidence
90% confidence
Finding
Generic read/write capabilities exceed what is typically needed for simple script generation and broaden the attack surface. In an agent setting, unnecessary file access can lead to unintended reading of sensitive local data or overwriting files if the skill is invoked inappropriately.

Context-Inappropriate Capability

Medium
Confidence
86% confidence
Finding
External API integration is not clearly tied to the declared purpose and introduces risks such as data exfiltration, hidden third-party dependencies, or unexpected network access. When paired with ambiguous documentation, users may not realize their inputs could be transmitted externally.

Intent-Code Divergence

High
Confidence
95% confidence
Finding
The description contradicts itself by describing a live-stream script generator while also claiming applicability to UI design, poster creation, and brand visuals. This inconsistency is dangerous because it obscures the true operating scope of the skill and can socially engineer broader invocation and permission grants than warranted.

Vague Triggers

Medium
Confidence
84% confidence
Finding
The invocation guidance is overly broad and ambiguous, making it easier for the skill to be triggered in contexts far beyond its intended use. In agent systems, vague routing criteria can cause over-invocation of a skill that has privileged tools, increasing exposure to sensitive files, commands, or external services.

Static analysis

No suspicious patterns detected.