Back to skill

Security audit

Ai Humanizer Backup

Security checks for vulnerabilities and agentic risk

Overview

This is a coherent local AI-writing analysis and rewriting skill, with caution needed around authorship claims and untrusted terminal output.

Install only if you want a local writing-style analyzer/humanizer. Do not use it to misrepresent authorship or bypass school, workplace, publishing, or compliance rules. Treat its AI scores as heuristic style feedback, and avoid running the CLI on untrusted text in an interactive terminal unless output is JSON or otherwise handled safely.

Vulnerability Patterns
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (1)

T09 · Insecure Skill Coding Practices

Warning
Location
src/cli.js:374
Finding

Unsanitized Attacker-Controlled Text Is Written to Interactive Terminals

Content
View full analysis
80 ? '...' : '') : ''; lines.push(` ${color.dim(loc)}: "${preview}"`); if (match.suggestion) { lines.push(` ${color.green('→')} ${match.suggestion}`); } ``` The grouped suggestion formatter also renders attacker-controlled matched text without sanitization: ```js lines.push(` ${color.dim(truncate(s.text, 60))}`); ``` This operation occurs in the critical, important, and minor suggestion sections at lines 417, 427, and 437. The autofix command prints the complete transformed input directly: ```js console.log(formatSuggestions(result)); if (flags.autofix && result.autofix) { console.log(`\n${color.bold('── AUTO-FIXED TEXT ──────────────────────────────')}\n`); console.log(result.autofix.text); console.log(`\n${color.dim('════════════════════════════════════════════════')}`); } ``` ### Technical Analysis The CLI accepts potentially untrusted text from a file or standard input. Portions of that text, and in the autofix case nearly the entire resulting document, are passed to `console.log` without removing terminal control characters. Truncating a string with `substring` does not neutralize ANSI escape sequences, Operating System Command sequences, carriage returns, backspaces, or other control characters. When output is connected to an interactive terminal, the terminal emulator may interpret these sequences rather than display them as ordinary text. Depending on terminal configuration and supported features, crafted input may: - Clea ...[truncated 1769 chars]
Remediation
View remediation
Vulnerability Patterns
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
Findings (21)

Tp4

High
Category
MCP Tool Poisoning
Confidence
99% confidence
Finding

The declared description describes a text-processing and rewriting skill focused on detecting and humanizing AI-generated writing. The actual code does not implement any text analysis or rewriting functionality. Instead, it configures ESLint for a JavaScript project, specifying recommended rules, file patterns, globals, and ignores. This is a materially different primary purpose and indicates a clear description-behavior mismatch.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
99% confidence
Finding

The declared description describes a text-processing and rewriting capability with detection heuristics and statistical analysis. The actual code chunk only configures a JavaScript test runner (Vitest) by setting globals and test file paths. This is a materially different primary purpose and provides none of the declared functionality. Therefore, the description does not accurately represent the supplied code.

Content

No source excerpt is available for this finding.

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 109)May include surrounding context.

md
echo "Your text here" | node src/cli.js score

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 112)May include surrounding context.

md
echo "Your text here" | node src/cli.js score

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 115)May include surrounding context.

md
echo "Your text here" | node src/cli.js score

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 118)May include surrounding context.

md
echo "Your text here" | node src/cli.js score

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 121)May include surrounding context.

md
echo "Your text here" | node src/cli.js score

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 124)May include surrounding context.

md
echo "Your text here" | node src/cli.js score

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 127)May include surrounding context.

md
echo "Your text here" | node src/cli.js score

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
70% confidence
Finding

Without declared permissions the skill's intent is opaque and cannot be validated.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

The invocation guidance is broad enough that the skill could trigger on generic writing-editing requests, not just explicit humanization tasks. In context, that matters because the skill is designed to remove AI-detection signals and make text appear human-authored, which can facilitate academic dishonesty, fraud, or policy evasion when applied automatically to ordinary drafting workflows.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

The skill explicitly offers 'de-AI writing' and AI-pattern scoring without any warning about integrity, deception, or policy concerns. That omission increases the risk the skill will be used to disguise machine-generated work as human-authored in settings like school, hiring, publishing, or compliance reviews, where provenance matters.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The summary logic makes categorical authorship claims such as 'The text looks human-written' and 'heavily AI-generated' based on heuristic scoring. In a skill explicitly designed to detect and 'humanize' AI text, these definitive statements can mislead users into over-trusting an unreliable classifier and enable policy evasion, fraud, or misrepresentation of authorship.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The user-facing labels map individual metrics directly to 'human-like' or 'AI-like' conclusions, which overstates what burstiness, vocabulary diversity, or repetition can prove. In this skill's context, those labels can encourage users to iteratively optimize text to evade AI-detection systems or accept false attributions as fact.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

The style tip explicitly encourages users to add first-person phrases such as "I found" and "In my experience" without verifying that those claims are true. In a skill whose stated purpose is to make AI-generated text sound more human, this can facilitate deceptive impersonation or fabricated personal experience, especially in reviews, testimonials, professional communications, or compliance-sensitive content.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
78% confidence
Finding

The file repeatedly states that certain stylometric patterns distinguish 'AI from human writing' and later labels low burstiness, low variation, and repetition as 'more AI-like' while contrasting them with 'human' writing. This natural-language framing presents a categorical authorship inference as policy guidance rather than a user choice or clearly bounded caveat, which is a semantic policy concern in the file text.

Content

No source excerpt is available for this finding.

Unpinned Dependencies

Low
Category
Supply Chain
Confidence
40% confidence
Finding

Dependencies lack version pinning, allowing potential malicious package updates. Consider pinning versions.

Content

Scanner excerpt · package.json (reported line 41)May include surrounding context.

json
"url": "https://github.com/brandonwise/humanizer"
  },
  "devDependencies": {
    "@eslint/js": "^9.39.2",
    "eslint": "^9.0.0",
    "prettier": "^3.0.0",
    "vitest": "^3.0.0"

Unpinned Dependencies

Low
Category
Supply Chain
Confidence
40% confidence
Finding

Dependencies lack version pinning, allowing potential malicious package updates. Consider pinning versions.

Content

Scanner excerpt · package.json (reported line 42)May include surrounding context.

json
},
  "devDependencies": {
    "@eslint/js": "^9.39.2",
    "eslint": "^9.0.0",
    "prettier": "^3.0.0",
    "vitest": "^3.0.0"
  },

Unpinned Dependencies

Low
Category
Supply Chain
Confidence
40% confidence
Finding

Dependencies lack version pinning, allowing potential malicious package updates. Consider pinning versions.

Content

Scanner excerpt · package.json (reported line 43)May include surrounding context.

json
"devDependencies": {
    "@eslint/js": "^9.39.2",
    "eslint": "^9.0.0",
    "prettier": "^3.0.0",
    "vitest": "^3.0.0"
  },
  "engines": {

Unpinned Dependencies

Low
Category
Supply Chain
Confidence
40% confidence
Finding

Dependencies lack version pinning, allowing potential malicious package updates. Consider pinning versions.

Content

Scanner excerpt · package.json (reported line 44)May include surrounding context.

json
"@eslint/js": "^9.39.2",
    "eslint": "^9.0.0",
    "prettier": "^3.0.0",
    "vitest": "^3.0.0"
  },
  "engines": {
    "node": ">=18.0.0"

Unverifiable Dependency: vitest has 3 known advisory(ies) (CVE-2026-47429 (When Vitest UI server is listening, arbitrary file can be read and executed); CVE-2026-84373 (Vitest: Path Traversal / Arbitrary File Read via @vitest/mocker Redirect Mock); CVE-2025-24964 (Vitest allows Remote Code Execution when accessing a malicious website while Vit)), but the manifest does not pin a version, so it is unknown whether the installed release is affected

Low
Category
Supply Chain
Confidence
78% confidence
Finding

The manifest declares vitest with an unpinned range despite known advisories affecting some vitest releases, so the project may resolve to a vulnerable version in development or CI. Because vitest is a devDependency and the package.json does not expose Vitest UI or mocker functionality at runtime, the skill context makes this less dangerous, but it still creates avoidable supply-chain and developer-environment risk.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.