Back to skill

Security audit

offline-knowledge-alignment

Security checks for vulnerabilities and agentic risk

Overview

This is a documentation-only skill with broad activation wording but no executable code, credential access, persistence, or hidden data movement.

Before installing, be aware that the skill may activate on broad knowledge or offline-related prompts. It appears safe as a documentation-only skill, but the publisher should narrow activation wording and add clearer subject-matter conditions.

Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (2)

Vague Triggers

Medium
Confidence
88% confidence
Finding
The trigger keywords are extremely generic terms such as "offline", "knowledge", and "alignment", which can cause the skill to activate for many unrelated prompts. Overbroad activation increases the chance that the wrong skill is invoked, leading to unintended behavior, prompt routing confusion, or policy bypass through accidental context injection.

Vague Triggers

Medium
Confidence
80% confidence
Finding
The statement that users can trigger the skill by asking in any supported language without needing a switch instruction is ambiguous about what content actually activates the skill. This ambiguity can cause unintended invocation across broad multilingual inputs, especially when combined with generic trigger terms, making routing less predictable and easier to misuse.

Static analysis

No suspicious patterns detected.