Back to skill

Security audit

Humanizer

Security checks for vulnerabilities and agentic risk

Overview

This skill is a disclosed text-editing helper for making prose sound less AI-generated, with no executable code, persistence, credential access, or hidden behavior found.

Install only if you want a writing editor that may rewrite documents to remove AI-sounding style markers. Do not use it to bypass academic, workplace, platform, or compliance rules that require disclosure of AI assistance, and review file edits before accepting them.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (4)

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The phrase "Or invoke directly when editing documents" is ambiguous about how and when the skill should activate. It does not define specific trigger phrases, constraints, or exclusion conditions, which could cause unintended invocation during normal document-editing workflows.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The skill’s stated purpose is to make text appear more human-written by removing signs of AI authorship, which can be used to conceal AI assistance or evade policies, reviewers, or provenance checks. The instructions go beyond ordinary copyediting by explicitly teaching stylistic laundering and adding 'personality' to mask machine-generated origin.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
89% confidence
Finding

The manifest description says the skill will "Remove signs of AI-generated writing from text" and "Detects and fixes AI patterns," but it does not define when the skill should activate, what inputs qualify, or any exclusion conditions. In a manifest file, this kind of broad phrasing can overlap with many ordinary editing requests and may cause unintended invocation.

Content

No source excerpt is available for this finding.

Missing User Warnings

Low
Category
Not specified by scanner
Confidence
88% confidence
Finding

The skill is granted Write and Edit capabilities, but its metadata and user-facing framing do not clearly warn that it may directly modify files rather than just suggest edits. This can lead to unintended content changes, especially if a user invokes the skill in a repository or notes directory expecting analysis-only behavior.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.