Back to skill

Security audit

Reading Coach Lite

Security checks for vulnerabilities and agentic risk

Overview

This is a prompt-only reading practice skill with no bundled code or install actions, though optional tool use could send student reading data to a connected education tool.

Install if you want a lightweight reading-comprehension helper. Avoid using real student identifiers or sensitive child data with optional connected tools unless you trust that tool, and review any companion plugin separately before installing it.

Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep

Static analysis

No suspicious patterns detected.