Back to skill

Security audit

brain-state-sleep-anxiety-cbti

Security checks for vulnerabilities and agentic risk

Overview

This skill is a disclosed sleep/anxiety self-help guide with medical disclaimers and no executable code, but users should treat it as educational rather than clinical advice.

Install this only if you want the agent to provide plain-language sleep and anxiety self-help guidance. Do not rely on it for diagnosis, medication decisions, crisis support, or severe or worsening symptoms; those should go to a qualified clinician or emergency support as appropriate.

Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (1)

Vague Triggers

Medium
Confidence
88% confidence
Finding
The trigger rules are broad enough to activate on generic sleep or anxiety discussions, which can cause the agent to deliver structured mental-health or sleep guidance in situations where the user did not explicitly request this specialized skill. In a health-adjacent skill, over-triggering increases the chance of unsolicited advice, mis-scoped responses, and accidental handling of sensitive mental-health content without adequate triage.

Static analysis

No suspicious patterns detected.