Security Audit
mattpocock/skills:skills/deprecated/ubiquitous-language
github.com/mattpocock/skillsTrust Assessment
mattpocock/skills:skills/deprecated/ubiquitous-language received a trust score of 85/100, placing it in the Mostly Trusted category. This skill has passed most security checks with only minor considerations noted.
SkillShield's automated analysis identified 1 finding: 0 critical, 0 high, 1 medium, and 0 low severity. Key findings include Indirect Command Injection via Example Dialogue.
The analysis covered 4 layers: Manifest Analysis, Static Code Analysis, Dependency Graph, LLM Behavioral Safety. All layers scored 70 or above, reflecting consistent security practices.
Last analyzed on July 17, 2026 (commit 9603c1cc). SkillShield performs automated 4-layer security analysis on AI skills and MCP servers.
Layer Breakdown
Behavioral Risk Signals
Security Findings1
| Severity | Finding | Layer | Location | |
|---|---|---|---|---|
| MEDIUM | Indirect Command Injection via Example Dialogue The skill's example dialogue contains instructions that mention running local shell commands ('the filesystem layer just runs those as local shell commands' and calling 'exec'). While intended as a domain modeling example, an LLM interpreting this example literally or attempting to execute the described 'sync service' or 'Sandbox service' could be misled into executing arbitrary shell commands or using unsafe APIs like `exec`. Revise the example dialogue to use a non-technical, purely business-oriented domain (e.g., e-commerce, logistics, or healthcare) that does not reference system-level operations like `exec`, Docker, or running local shell commands. | LLM | SKILL.md:64 |
Scan History
Embed Code
[](https://skillshield.io/report/0f31d9e2a982430c)
Powered by SkillShield