Skip to content
Report library
Purpose / Other

To Questionnaire Skill Security Audit

What the author says it does (original text)

Turn a decision you can't fully answer into a questionnaire for someone else to fill in.

Independent security check

Low-risk issues found

Files checked
2
Risks found
1
Could it run dangerous commands?Looks for programs run straight after downloading, remote control of your computer, and hidden commands.No risks found
Could it expose your files or keys?Looks for uploads of files containing passwords or keys, and keys written directly in the code.Risks found: 1
Low risk

The generated questionnaire may persist and disclose relationships or sensitive decision context

Source references: 2
What we found

The template requires the sender, recipient, intended use, decision context, and enough background for the recipient to answer. The Skill does not require a privacy, confidentiality, or recipient-authorization check before saving or handing over the document.

Why this matters

If the user supplies sensitive personnel, customer, business, or technical details, they may remain in a Markdown file in the current directory and be disclosed when the questionnaire is shared or when others can access that directory.

What this evidence establishes

The Skill does require saving the questionnaire in the current directory and including the sender, recipient, intended use, decision context, and enough background to answer. If the user supplies personal or confidential project details, the saved file would retain them. However, this is part of the stated purpose of gathering information from a user-chosen recipient. The source neither requires sensitive data nor sends the file or exposes it to an unauthorized person, so it supports only a conditional retention risk, not improper disclosure. A user can restrict names, confidential context, and the save location.

This assessment concerns the code and conditions shown, not proof that harm has occurred.
SKILL.md:16In the instructionsOpen original file
3. **Write the questionnaire.** Draft questions aimed at the gap from steps 1–2, following the Document structure below. Write it to `to-questionnaire-<slug>.md` in the current directory (slug from the topic) and report the path. Done when the file exists and every item the user named in step 2 is covered by a question.
Show 1 other places
SKILL.md:26In the instructionsOpen original file
**Purpose:** why this questionnaire exists and the decision riding on it.**From:** <the user>, **To:** <the recipient>, **How your answers will be used:** <where they go>## ContextOne paragraph orienting a recipient who wasn't in the user's head. Enough to answer well, not a page.
Could it delete files or keep running?Looks for broad file deletion, disk overwrites, and programs set to start automatically.No risks found
Could it bypass safety checks?Looks for skipped website security checks, excessive file access, or actions that skip your approval.No risks found
Could it mislead the AI or hide text?Checks the skill instructions for requests to ignore you, influence the report, or hide text in invisible characters.No risks found
Could it change links or payment recipients without asking?Looks for forced referral or payment changes combined with instructions to hide the change.No risks found

Inside this skill

1 instruction sections

The Skill first asks about the recipient’s role, expertise, and relationship to the user, then asks which facts or decisions the user needs from that person; the questionnaire is focused on the knowledge gap between them.

View source
SKILL.md:12In the instructionsOpen original file
1. **Who is it going to?** Ask, in one exchange, the recipient's role, expertise, and relationship to the user. This fixes the questionnaire's tone and how much context it must carry. Done when you know who the recipient is and what they know that the user doesn't.2. **What do you need back?** Ask, in one exchange, the specific decisions or facts the user can't resolve alone and needs from this person. Done when you have a concrete list of what the user must walk away able to do or decide.

It creates a Markdown file in the current directory and requires the questionnaire to cover every need listed by the user.

View source
SKILL.md:16In the instructionsOpen original file
3. **Write the questionnaire.** Draft questions aimed at the gap from steps 1–2, following the Document structure below. Write it to `to-questionnaire-<slug>.md` in the current directory (slug from the topic) and report the path. Done when the file exists and every item the user named in step 2 is covered by a question.

The configuration disables implicit invocation, so the Skill should be explicitly triggered by the user rather than automatically run for a similar topic.

View source
SKILL.md:4In the instructionsOpen original file
description: Turn a decision you can't fully answer into a questionnaire for someone else to fill in.disable-model-invocation: true---
agents/openai.yaml:4In the instructionsOpen original file
  short_description: "Front-load questions into a doc for someone to answer"policy:  allow_implicit_invocation: false
Start here · InstructionsSKILL.md
to-questionnaire
Lines connect the instruction file to its sections, not an observed execution order. Select a section to read the source.
Files and check records2 files

Coverage and gaps

Content covered in each file

These are the source ranges included in this check, not a guarantee that every issue has been resolved.

  • SKILL.mdFull text included
  • agents/openai.yamlFull text included

This report is for the version above. We read the available code and instructions without running the skill or checking extra packages it installs. This is not a promise of safety: a different version or setup may behave differently.

  • SKILL.mdInstructions
  • agents/openai.yamlSupporting file
Lines read
61
File checksum (to compare versions)
61ccfd13b55f06922c7a6b02fc9ca0e31498fe0c5f4533447516dc1a06a3f539