Back to skill

Security audit

psychology-paper-reviewer

Security checks for vulnerabilities and agentic risk

Overview

This is a text-only psychology paper review skill with no code execution, data access, persistence, or hidden behavior.

Install this if you want structured psychology manuscript feedback. Be aware that it may answer in Chinese and may activate for broad peer-review requests unless the router or skill metadata is tightened.

Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (2)

Vague Triggers

Medium
Confidence
90% confidence
Finding
The invocation description uses broad trigger phrases like '检查' and 'review this psychology paper' that can overlap with generic requests for feedback, checking, or critique. This can cause the router to invoke the skill for unrelated inputs, leading to prompt hijacking of task routing, incorrect behavior selection, or unintended disclosure/transformation of user content under the wrong workflow.

Natural-Language Policy Violations

Medium
Confidence
84% confidence
Finding
The skill content is written as Chinese-only and does not offer a user-language fallback or explain a strict locale constraint, even though the trigger list includes English phrases. This can produce mismatched-language responses, reduce user comprehension, and create safety/reliability issues if users misunderstand methodological critique or recommendations.

Static analysis

No suspicious patterns detected.