Back to skill

Security audit

a3-law-operational

Security checks for vulnerabilities and agentic risk

Overview

This is a policy guidance skill for AI governance, with no executable code or hidden data access, though its trigger keywords are broader than ideal.

This skill is reasonable to install if you want governance prompts for AI self-modification or agent autonomy reviews. Be aware that its broad trigger words may load it during unrelated conversations about law or operations, so users should confirm it is relevant before relying on its advice.

Vulnerability Patterns
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
Findings (4)

Vague Triggers

Medium
Confidence
92% confidence
Finding
The read_when conditions are broad and semantically expansive, including generic situations like generating/modifying another AI, high-impact autonomous actions, or mentioning terms such as self-modification and thresholds. In a skill that frames governance decisions, this can cause unintended activation in many unrelated conversations and may let the skill inappropriately steer decisions or override more specific safety/review flows.

Vague Triggers

Medium
Confidence
95% confidence
Finding
The trigger keywords are extremely generic: terms like 'a3', 'law', and 'operational' are common across benign contexts and are not uniquely tied to this skill. Such vague discovery signals increase accidental invocation and create opportunities for prompt collision, where unrelated user inputs activate a governance skill that can bias routing, advice, or control decisions.

Vague Triggers

Medium
Confidence
87% confidence
Finding
The manifest description contains many broad trigger phrases and synonyms related to AI governance, self-modification, and agent autonomy. In systems that route or auto-invoke skills by keyword matching, this can cause unintended activation outside the author’s precise scope, leading to overbroad invocation and possible policy misapplication or user confusion.

Natural-Language Policy Violations

Medium
Confidence
78% confidence
Finding
The description is written in Chinese without indicating whether the skill is Chinese-only or how language selection should be handled. In multilingual environments this can cause misrouting, misunderstanding of capability, or activation for users who cannot evaluate the skill’s purpose, which is an operational safety issue rather than a direct exploit.

Static analysis

No suspicious patterns detected.