Back to skill

Security audit

Good Name Skill

Security checks for vulnerabilities and agentic risk

Overview

The skill appears to be an output-guidance skill with a language-preference issue, not a security or data-access risk.

Installers should expect the skill to bias outputs toward Chinese or mixed-language formatting in some places. Use it when that is acceptable, and prefer an updated version if you need language to strictly follow the user's request.

Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Findings (2)

Natural-Language Policy Violations

Medium
Confidence
91% confidence
Finding
The skill description hard-codes Chinese output behavior, which can override or bias the assistant away from the user's preferred language. This is not a memory-safety issue, but it can cause policy and UX failures by reducing user control and creating accessibility or compliance problems in multilingual contexts.

Natural-Language Policy Violations

Medium
Confidence
95% confidence
Finding
The English naming template still requires Chinese-constrained content ('within 20 Chinese characters'), which is inconsistent with an English-language flow and can force mixed-language output without user consent. In practice this may confuse users, degrade output quality, and violate expected language-selection behavior.

Static analysis

No suspicious patterns detected.