Back to skill

Security audit

Handwriting Analysis

Security checks for vulnerabilities and agentic risk

Overview

This skill has no executable malware indicators, but it directs agents to make sensitive personality, mental-state, and criminal-risk judgments from handwriting in forensic and personnel contexts.

Install only if you understand this as speculative graphology guidance, not a reliable forensic, hiring, mental-health, or law-enforcement assessment tool. Do not use it to judge a person’s dangerousness, honesty, mental state, employability, or guilt, especially from third-party handwriting without informed consent.

Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Findings (2)

Missing User Warnings

Medium
Confidence
94% confidence
Finding
The skill invites users to upload handwriting images for analysis without a clear upfront warning that such images may contain sensitive personal data, signatures, identifiers, or contextual clues that could be used for evaluative or investigative judgments. In a forensic/personality-analysis context, this omission increases privacy and misuse risk because users may not understand the sensitivity of what they are submitting or how consequential the inferences may be.

Natural-Language Policy Violations

High
Confidence
98% confidence
Finding
The skill explicitly instructs the agent to infer personality traits, psychological state, and behavioral tendencies from handwriting as though these are reliable determinations. That is dangerous because it encourages unsupported psychological profiling and potentially forensic conclusions from weak or pseudoscientific signals, which can lead to discriminatory, stigmatizing, or high-stakes errors, especially in criminal-investigative or personnel-evaluation settings.

Static analysis

No suspicious patterns detected.