xunbo-writing-style

Fail

Audited by Socket on Mar 2, 2026

1 alert found:

Obfuscated File
Obfuscated FileHIGH
SKILL.md

The specification correctly captures the stylistic and structural constraints needed to generate prose in the target voice. However, its mandatory post-generation side effects (writing /tmp/xunbo_output.txt and executing a Bash pipeline to call pbcopy) are unnecessary for the core goal and introduce an avoidable operational security risk: they require filesystem and shell privileges, assume a specific OS utility, and increase potential for local data exposure or abuse. No direct malware or remote exfiltration is present in the prompt itself, but the enforced shell step is an enabling vector that should be removed or gated behind explicit user consent and environment checks.

Confidence: 98%
Audit Metadata
Analyzed At
Mar 2, 2026, 04:13 PM
Package URL
pkg:socket/skills-sh/geeprox%2Fmy-skills%2Fxunbo-writing-style%2F@83d708103459c7649696dbf802999f12ea06132e