Back to skill

Security audit

ELI5-TLDR

Security checks for vulnerabilities and agentic risk

Overview

This skill only adds optional ELI5/TLDR prompts after complex answers and does not show code execution, data access, persistence, or hidden behavior.

Install this only if you want complex responses to routinely include ELI5/TLDR options. Avoid or disable it for workflows that require exact JSON, code-only output, concise answers, or no extra appended text.

Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (2)

Vague Triggers

Medium
Confidence
95% confidence
Finding
The skill declares itself 'Always active. No trigger needed,' which makes it apply broadly across unrelated conversations without clear scoping. Over-broad activation can interfere with normal system behavior, create noisy or undesired output, and increase the chance that the skill hijacks responses in contexts where simplification is inappropriate.

Vague Triggers

Low
Confidence
83% confidence
Finding
The invocation criteria rely on subjective conditions like 'complex explanation' and 'user might want quick summary,' which are open to inconsistent interpretation. This ambiguity can cause the skill to trigger unpredictably, leading to unnecessary response modification and reduced reliability of agent behavior.

Static analysis

No suspicious patterns detected.