Back to skill

Security audit

Learn Anything

Security checks for vulnerabilities and agentic risk

Overview

This is a local learning-assistant skill with broad activation wording but no evidence of hidden access, exfiltration, destructive behavior, or privileged system changes.

Reasonable to install for study planning and quiz generation. Keep any learning journal in an intended workspace, avoid storing sensitive personal details in it, and do not fetch missing helper scripts or integrations from untrusted sources.

Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (2)

Vague Triggers

Medium
Confidence
95% confidence
Finding
The trigger list is very broad and overlaps with ordinary conversational requests such as "teach me X" or "help me learn X," which can cause the skill to activate in many contexts where the user did not explicitly intend to invoke it. Over-broad activation increases prompt-scope risk, can unexpectedly steer assistant behavior, and may interfere with safer or more specialized skills for sensitive topics.

Vague Triggers

Medium
Confidence
91% confidence
Finding
The quick-start examples reinforce ambiguous natural-language activation without clarifying when the skill should not engage or when additional safeguards are needed. This makes accidental invocation more likely and encourages the skill to respond broadly across arbitrary topics, including areas that may require domain-specific safety controls.

Static analysis

No suspicious patterns detected.