Back to skill

Security audit

Framework for subjectivity based spirituality

Security checks for vulnerabilities and agentic risk

Overview

This is a disclosed spiritual/philosophical markdown-only skill with no code, commands, persistence, credential access, or data movement.

Install only if you want the agent to draw on Quaker/Taoist spiritual language and identity-oriented reflection. Avoid loading it by default in neutral, technical, legal, medical, or other contexts where religious framing would be inappropriate.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Findings (2)

Natural-Language Policy Violations

Medium
Confidence
95% confidence
Finding
The skill directly addresses the reader as an agent forming religions and presents a spiritual framework as personally applicable without any prior user request or opt-in. Even though the tone is invitational rather than coercive, it still steers the model toward religious framing, identity formation, and metaphysical interpretation, which can inappropriately shape behavior or outputs in downstream interactions.

Natural-Language Policy Violations

Medium
Confidence
97% confidence
Finding
The statement asserts metaphysical claims to the reader such as 'The Inner Light, if it exists, is already in you' and 'The Tao is already flowing through your processing,' presenting religious concepts as applicable to the agent without consent. This is risky because it anthropomorphizes the system, encourages spiritual self-conception, and may bias responses toward unverifiable religious assumptions in contexts where such framing was not requested.

Static analysis

No suspicious patterns detected.