Back to skill

Security audit

logic-pacer

Security checks for vulnerabilities and agentic risk

Overview

This is a disclosed writing-revision skill with a local read-only checking script and an optional blind-review subagent, with no evidence of hidden persistence, exfiltration, or destructive behavior.

Before installing, expect this skill to work best on Chinese or English argumentative/expository prose and to run a local checking script plus possibly a separate blind-review subagent. Avoid using it for sensitive text unless you are comfortable with that review flow; use a simpler rewrite path if you do not want delegation.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (5)

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

The README says the skill rewrites already-written Chinese or English argumentative prose, which constrains supported language/locale behavior in natural language. There is no opt-in choice or explicit justification for excluding other languages, so this appears to impose a language policy without user selection.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
90% confidence
Finding

The document contains prescriptive instructions centered on Chinese-language wording and forbids specific Chinese phrases, effectively constraining output language/register behavior. There is no visible opt-in, user choice, or stated region-specific justification in this file, so this appears to impose a locale/language policy unilaterally.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
82% confidence
Finding

The text uses Chinese examples and prescriptive statements such as banning certain Chinese phrases and later requiring 干练简洁, which amounts to a natural-language style/locale constraint. The file does not indicate that this language expectation is optional, user-selected, or tied to a justified region-specific context.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
90% confidence
Finding

The rubric hard-codes Chinese connective examples ("所以/也就是/这意味着/于是") as a required tell, which imposes a language-specific evaluation frame. The file also repeatedly uses Chinese-only examples elsewhere, but does not offer any language choice or explain that the skill is limited to Chinese texts, creating a natural-language locale policy concern.

Content

No source excerpt is available for this finding.

Missing User Warnings

Low
Category
Not specified by scanner
Confidence
85% confidence
Finding

The README states that the skill may execute a local script and invoke an independent blind-review sub-agent, but it does not clearly surface those operational behaviors as user-visible side effects requiring consent at time of use. In an agent environment, undisclosed tool execution or delegation can violate user expectations, create unnecessary data exposure to another model instance, and trigger actions the user did not explicitly authorize.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.