Back to skill

Security audit

apa-experiment-generator

Security checks for vulnerabilities and agentic risk

Overview

This skill is a disclosed academic writing helper for psychology APA method sections and does not request tools, credentials, persistence, or system access.

Installers should understand this is an academic drafting aid, not a source of verified study design, APA compliance, ethics approval, or real statistical evidence. Users should review generated text carefully and narrow the triggers if accidental activation in unrelated writing tasks is a concern.

Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (2)

Vague Triggers

Medium
Confidence
91% confidence
Finding
The trigger phrase "我要写毕业论文" is very broad and can match many ordinary academic requests that are not specifically asking for experiment-method generation. Overly broad activation increases the chance this skill is invoked in the wrong context, causing unintended prompt routing, confusing outputs, or bypass of more appropriate domain-specific skills.

Vague Triggers

Medium
Confidence
84% confidence
Finding
The trigger phrase "/写方法节" is ambiguous because it does not specify psychology, APA, or experiment design, so it could match many unrelated writing tasks. This ambiguity can lead to accidental invocation and misclassification of user intent, reducing reliability and potentially exposing users to irrelevant or malformed outputs.

Static analysis

No suspicious patterns detected.