Back to skill

Security audit

Logos(诺声)

Security checks for vulnerabilities and agentic risk

Overview

This is a disclosed writing/persona skill for brand and thought-leadership content, with no code execution, credentials, persistence, or hidden data access.

This skill appears safe to install as a writing style and signature guide. Use it when you intentionally want the Logos brand/persona voice for public-facing thought-leadership or narrative content, and avoid relying on it for legal, regulatory, financial, medical, or other expert decisions.

Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (1)

Vague Triggers

Medium
Confidence
86% confidence
Finding
The activation rule is broad enough to trigger on common writing tasks such as external viewpoints, theory articles, brand narrative, and speeches. In a multi-skill agent, this can cause the persona/branding skill to be invoked in situations where a more task-specific or safety-constrained skill should apply, increasing the chance of inappropriate scoped outputs or instruction interference.

Static analysis

No suspicious patterns detected.