Back to skill

Security audit

zayn-responsibility

Security checks for vulnerabilities and agentic risk

Overview

This skill is a disclosed checklist for handling hardware aftersales responsibility questions and does not ask for system access or automatic actions.

Before installing, treat this as an internal responsibility-boundary aid for hardware aftersales cases, not as legal advice or authorization to deny service, refund, exchange, or compensate. For general products, services, or project responsibility questions, use the referenced general responsibility workflow instead.

Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (1)

Vague Triggers

Medium
Confidence
90% confidence
Finding
The applicability section says the skill is suitable for scenarios requiring complaint handling, responsibility, returns/exchanges, or aftersales duties, which is broad enough to trigger in routine support cases outside its intended narrow boundary. In a responsibility-assessment skill, over-triggering can cause the agent to apply restrictive liability language, defer normal support actions, or mishandle customer communications in contexts where a different workflow should be used.

Static analysis

No suspicious patterns detected.