Ae1
- Category
- analysis-evasion
- Confidence
- 100% confidence
- Finding
Referenced artifact was not completely inspected
- Content
md 4. Write a clean `SKILL.md` with trigger conditions, steps, and optional arguments.
Security audit
Security checks for vulnerabilities and agentic risk
This skill coherently helps turn a completed workflow into a reusable SKILL.md file, with no hidden code execution or unrelated access found.
Before installing or using this skill, confirm the exact save location for generated skills, review the SKILL.md before keeping it, and avoid including secrets or sensitive session details in reusable instructions.
Referenced artifact was not completely inspected
4. Write a clean `SKILL.md` with trigger conditions, steps, and optional arguments.
The trigger/description is broad enough to match many ordinary end-of-session interactions, which can cause the skill to activate in contexts where the user did not explicitly request file generation or persistence. In this skill’s context, that matters because activation leads toward producing and saving a SKILL.md, increasing the chance of unintended repository or user-file modification.
The workflow explicitly instructs saving a generated skill file but does not require confirmation before writing to repo-level or personal locations, nor does it warn about modifying user-controlled files. In an agent setting, this can lead to unauthorized or surprising persistence, overwriting existing artifacts, or making repository changes the user did not intend.
No suspicious patterns detected.