T09 · Insecure Skill Coding Practices
- Location
references/examples.md:191- Finding
Rewriting Rules Encourage Fabricated Experiences and Altered Quantitative Claims
- Content
View full analysis
Vulnerability Details
File Location:
SKILL.md:34,88,115,128-129,282;references/banned-words.md:160;references/examples.md:179,191
Vulnerability Type: Content-integrity failure caused by unsafe rewriting instructions
Risk Level: MediumEvidence
SKILL.md:34states:text Only change how the content is expressed, not what it says. Do not alter the plot, characterization, or story direction. Do not add content absent from the source.SKILL.md:88subsequently instructs:text Add specific sensory details.references/banned-words.md:160instructs:text Replace hypothetical examples with a currently occurring real scenario.references/examples.md:179reinforces that instruction:text Hypothetical examples are prohibited; use real details about something currently happening.references/examples.md:191explicitly approves changing a numerical claim:text The number was changed from 6 to 2 to make the statement more extreme and impactful.Technical Analysis
The skill is intended to perform stylistic editing, but several rules cross the boundary into substantive content generation. Instructions to add sensory details, convert hypothetical examples into purportedly real experiences, inject personal perspective, and alter numbers can introduce claims that were never supplied or verified by the user.
The numerical example is particularly unsafe because it treats factual modification as a rhetorical technique. This conflicts directly with the fidelity rule in
SKILL.md:34. Because the quality checks also reward personal experience, distinctiveness, and specific details, the unsafe behavior may be applied systematically rather than exceptionally.This issue is classified as
T09: Insecure Skill Coding Practicesbecause the unsafe behavior originates in the skill configuration and its mandatory processing rules. No executable-code vul ...[truncated 1687 chars]- Remediation
View remediation
Remediation Suggestions
- Establish factual fidelity as a mandatory rule that overrides all style guidance.
- Preserve names, dates, quotations, measurements, quantities, statistics, and factual claims exactly unless the user explicitly requests and authorizes substantive changes.
- Remove the example approving the change from 6 to 2 for rhetorical impact.
- Replace the instruction to use a “real scenario” with guidance to retain the hypothetical framing or request a verified example from the user.
- Change “add specific sensory details” to “retain and clarify sensory details already present in the source.”
- Prohibit invented personal experiences, emotions, opinions, attribution, and firsthand observations.
- If additional specificity is needed, insert an explicit placeholder or ask the user for supporting facts rather than generating them.
- Add a mandatory quality-control check that compares the rewritten output with the source and flags every changed factual token, including numbers, dates, proper nouns, units, and quotations.
- Require the output to disclose any user-authorized substantive alteration separately from stylistic edits.
- Resolve conflicting instructions by explicitly stating that content preservation takes precedence over humanization, distinctiveness, emotional tone, and rhetorical impact.
