Back to skill

Security audit

method-logic-diagnostic

Security checks for vulnerabilities and agentic risk

Overview

This skill is a disclosed academic writing diagnostic tool, with no hidden execution or data-transfer behavior, though users should treat its local Windows reference paths and limitation-framing advice carefully.

Install only if you want a Chinese-language psychology Method-section diagnostic assistant. Be aware that the packaged skill mentions machine-specific Windows reference paths that may not exist on your system, and review any suggested limitation wording to ensure it remains accurate and transparent rather than overly polished.

Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (3)

Context-Inappropriate Capability

Medium
Confidence
94% confidence
Finding
The skill hard-codes access to a Windows absolute-path PDF and an external junctioned example repository, expanding the skill’s trust boundary from the provided input to host-local files. In an agent environment, this can disclose filesystem structure, couple behavior to machine-specific resources, and enable unintended retrieval of local content unrelated to the user’s request.

Natural-Language Policy Violations

Medium
Confidence
91% confidence
Finding
The checklist instructs authors to present limitations using minimizing language, which can encourage understatement of important methodological weaknesses rather than clear disclosure. In a skill designed to diagnose and improve Method sections, this guidance can systematically bias outputs toward polished but less transparent reporting, potentially misleading reviewers or readers about study validity.

Natural-Language Policy Violations

Medium
Confidence
97% confidence
Finding
These lines explicitly prescribe 'minimalizing problem/responsibility' wording and 'maximizing advantage' wording for limitation disclosure, which directly incentivizes spin. That is dangerous because it operationalizes deceptive framing as a writing norm, especially in a scholarly-methods skill where users may adopt the language to obscure uncertainty, underpowering, or external-validity problems.

Static analysis

No suspicious patterns detected.