Back to skill

Security audit

Token Economist Free

Security checks for vulnerabilities and agentic risk

Overview

This skill is a disclosed token-optimization helper that summarizes conversation context and reuses cached answers, with no artifact evidence of hidden exfiltration, destructive actions, or persistent background behavior.

Install this only if you want the agent to summarize older conversation context and reuse similar prior answers to save tokens. Avoid using it for highly sensitive sessions unless you are comfortable with session-level caching and summarization, and use the documented clear-cache or disable commands when needed.

Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (3)

Vague Triggers

Medium
Confidence
90% confidence
Finding
The skill uses broad natural-language trigger phrases like 'Token状态' or similar mode-switching requests without clear scoping or confirmation boundaries. This can cause accidental activation during ordinary conversation, leading the agent to compress, cache, or alter context handling unexpectedly, which may affect confidentiality, reliability, or task integrity.

Vague Triggers

Medium
Confidence
92% confidence
Finding
The skill claims very broad keyword-based coverage across many generic concepts without defining strict activation constraints or exclusions. In an agent environment, that increases the chance of unintentional triggering on unrelated tasks, causing hidden context transformation or cached-response reuse in situations where users did not consent to such behavior.

Missing User Warnings

Medium
Confidence
94% confidence
Finding
The skill describes context compression and semantic caching but does not clearly warn users that prior conversation content may be retained, summarized, or reused in later responses. In a tool-enabled agent, silent retention and reuse of prior content can expose sensitive information across turns or produce responses influenced by earlier private context without informed user consent.

Static analysis

No suspicious patterns detected.