Back to skill

Security audit

results-tense-grammar-checker

Security checks for vulnerabilities and agentic risk

Overview

This is a narrow writing-assistance skill for checking grammar and tense in psychology Results sections, with no hidden execution, persistence, or data-access behavior found.

Installers should expect a Chinese-language workflow for reviewing English Results-section drafts. Users who want English output should state that preference explicitly, but no security-relevant overreach was found in the artifacts inspected.

Vulnerability Patterns
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (1)

Natural-Language Policy Violations

Medium
Confidence
95% confidence
Finding
The skill metadata and rubric are written in Chinese and explicitly target Chinese-speaking usage, which can force a specific language/locale without checking the user's preference. This can reduce usability, exclude users, and cause incorrect or inaccessible outputs when the caller expects another language, especially in multi-tenant or international environments.

Static analysis

No suspicious patterns detected.