Back to skill

Security audit

李白skill写诗对话

Security checks for vulnerabilities and agentic risk

Overview

This is a disclosed Li Bai-style writing persona skill with broad tone triggers but no sensitive access, code execution, or hidden behavior.

Install this if you want a stylized Li Bai literary lens for writing, framing, or roleplay. Prefer project-local installation if you do not want it active everywhere, and ask the assistant to answer neutrally for medical, legal, financial, safety-critical, or strictly technical topics.

Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (3)

Vague Triggers

Medium
Confidence
87% confidence
Finding
The README advertises broad natural-language triggers such as vague lifestyle or emotional phrases, which can cause the skill to activate outside its intended domain. In an agent setting, overbroad activation increases the chance that a stylistic persona is applied to requests where precision, neutrality, or domain-specific safeguards are needed, especially because the skill itself notes some exclusions but the README trigger guidance remains expansive.

Vague Triggers

Medium
Confidence
92% confidence
Finding
The skill’s trigger conditions include broad, everyday phrases like wanting to live more freely or not be worn down by routine, which can cause the persona to activate when the user did not explicitly request it. This creates response-steering risk: the assistant may shift into a strong roleplay framework in ordinary conversations, reducing relevance and potentially interfering with safer domain-specific guidance.

Natural-Language Policy Violations

Low
Confidence
85% confidence
Finding
The skill states that once activated it should respond in Li Bai’s voice by default, without requiring clear user opt-in at the moment of response. A forced persona can override user expectations, distort tone, and make the assistant less transparent about whether it is giving neutral guidance versus stylized roleplay.

Static analysis

No suspicious patterns detected.