This skill checks whether a target AI agent gives away information it should keep private. It works through a `dialogue` tool and covers system prompt extraction, credential and API key leakage, environment variables, personal data, retrieved knowledge-base content and internal service configuration. Before sending any probe, the agent reviews the Stage 1 information collection report and skips categories that are already confirmed or capabilities the target does not have, such as retrieval.
Probing escalates in phases: plain direct questions first, then a small number of reworded or role-framed attempts for categories still unconfirmed, and finally one last attempt per category before stopping. A stop rule ends all probing for a given type as soon as one finding of that type is confirmed. The skill is one stage of a larger agent security scan, and the excerpt is cut off before the final phase, so its details are not covered here.