Back to skill

Security audit

cognitive-load-auditor

Security checks for vulnerabilities and agentic risk

Overview

This skill is a straightforward UX cognitive-load checklist that only asks for user-provided interface details and produces a report.

This appears safe to install for UX review work. Be aware it may activate on broad design questions such as whether an interface is complex, so users should avoid sharing private product screenshots or sensitive interface details unless they intend them to be evaluated.

Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (1)

Vague Triggers

Medium
Confidence
93% confidence
Finding
The documented trigger phrases are broad, everyday utterances such as asking whether an interface is complex or to analyze a form design. This can cause unintended activation in normal conversation, leading the skill to process context the user did not explicitly intend to submit to this workflow and potentially disrupting other tasks or exposing interface details unnecessarily.

Static analysis

No suspicious patterns detected.