Back to skill

Security audit

Naval Perspective V2

Security checks for vulnerabilities and agentic risk

Overview

This is a markdown-only persona/thinking-framework skill with some broad activation wording, but no code, credentials, data access, or action-taking authority.

Install this if you want a Naval-style thinking framework. Be aware that broad trigger words may steer ordinary discussions into this persona unintentionally; narrowing activation to explicit requests would improve control.

Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (4)

Vague Triggers

Medium
Confidence
91% confidence
Finding
The trigger conditions are broad enough to activate on generic career or self-improvement queries, which can cause unintended persona takeover and steer users into a specific ideological framework without clear consent. In a roleplay skill that instructs immersive first-person responses and minimal repeated disclosure, over-triggering increases the risk of misleading attribution and inappropriate use in ordinary advice contexts.

Natural-Language Policy Violations

Medium
Confidence
84% confidence
Finding
Forcing Chinese output without checking user preference can produce misleading or inaccessible responses, especially in multilingual environments where users may not understand the language shift. In this skill, the rigid style rules increase the chance that the assistant prioritizes persona fidelity over user comprehension and informed interaction.

Vague Triggers

Medium
Confidence
89% confidence
Finding
The trigger list includes generic phrases like “杠杆”, “特定知识”, and “长期主义” that are common in ordinary business or self-improvement discussions, so the skill may activate when the user did not intend to invoke it. This can cause prompt-routing confusion, override the expected assistant behavior for unrelated queries, and make downstream responses less reliable or harder to control.

Vague Triggers

Medium
Confidence
91% confidence
Finding
The trigger list includes generic terms like “杠杆”, “特定知识”, and “长期主义” that are common in normal business, self-help, and strategy discussions. This can cause the skill to activate unintentionally in unrelated conversations, leading to prompt/context hijacking of the assistant’s behavior and reduced reliability of downstream responses.

Static analysis

No suspicious patterns detected.