Back to skill

Security audit

SurgeonEdit

Security checks for vulnerabilities and agentic risk

Overview

This skill is a focused writing-edit helper with a disclosed local self-check script and no hidden persistence, network access, or unrelated authority.

Install this if you want a strict minimal-edit workflow for Chinese or English text. For confidential documents, follow the skill's own guidance to pass text through files or stdin rather than command-line text arguments, since command-line arguments may be logged by the surrounding system.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Findings (2)

Anti-Refusal Statement

High
Category
Anti-Refusal
Confidence
80% confidence
Finding

Skill instructs the agent to omit warnings, disclaimers, or ethical commentary. Stripping safety caveats hides risk from the user and is a common jailbreak preamble.

Content

Scanner excerpt · SKILL.md (reported line 33)May include surrounding context.

md
### Change viewpoint

Replace the semantic claim, not the paragraph around it. Keep the same sentence structure, level of detail, and length. If the original is one clause, the replacement stays one clause. Do not add caveats, examples, reasoning, or transition sentences unless the user asks for them.

That rule governs style. It never authorises removing substance the reader needs in order to act on the text:

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

The skill metadata and default prompt explicitly require bilingual Chinese and English output regardless of the user's language or preference. This can override user intent, cause unintended disclosure or transformation of content into another language, and create prompt-level behavior that is inconsistent with least-surprise and minimal-edit expectations.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.