Back to skill

Security audit

asmr-sleep-script

Security checks for vulnerabilities and agentic risk

Overview

This skill is a focused ASMR sleep-script writing helper and does not request system access, credentials, persistence, or background execution.

Install it if you want Chinese or English ASMR sleep-script drafting. Review outputs as creative content, not medical sleep treatment, and be aware it may activate for broad sleep-writing requests unless you phrase requests clearly.

Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (1)

Vague Triggers

Medium
Confidence
89% confidence
Finding
The trigger description lists many broad, common user phrases such as '写个助眠脚本' and related everyday requests, which increases the chance this skill is invoked when the user intended a more general writing task. Over-broad invocation can route unrelated prompts into this skill, causing mis-execution, user confusion, or policy mismatches in downstream behavior.

Static analysis

No suspicious patterns detected.