Back to skill

Security audit

altshuller-perspective

Security checks for vulnerabilities and agentic risk

Overview

This is a TRIZ/Altshuller analysis persona skill with a disclosed optional external MCP/database dependency, but no executable code or hidden high-impact behavior was found.

Before installing, treat this skill primarily as a TRIZ reasoning/persona guide. If you enable the Zhihuiya MCP service, expect third-party account authorization and live database lookups; outputs from those lookups should be labeled as modern/tool-derived evidence, not as Altshuller’s own historical views.

Vulnerability Patterns
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (2)

Description-Behavior Mismatch

Medium
Confidence
83% confidence
Finding
The skill is presented as a historically grounded Altshuller/TRIZ persona distilled from fixed literature, but the later MCP section expands behavior into live data retrieval and database-backed conclusions. That mismatch can mislead users about provenance, recency, and whether outputs reflect Altshuller’s documented views versus modern external data, increasing the risk of authority laundering and incorrect decisions.

Intent-Code Divergence

Medium
Confidence
79% confidence
Finding
The file states the skill excludes post-1998 TRIZ developments, yet later claims it can fetch real-time data and generate database-based conclusions via MCP. This inconsistency can cause users to overtrust outputs as bounded, historically faithful analysis when the skill may instead blend in current external information without clear attribution.

Static analysis

No suspicious patterns detected.