Back to skill

Security audit

零售散户决胜法

Security checks for vulnerabilities and agentic risk

Overview

This is a crypto-investing analysis prompt with broad triggers and weak risk warnings, but it does not run code, access user data, or perform transactions.

Install this only if you want a retail-focused crypto opportunity framework. Before acting on its conclusions, independently verify current market data, token unlock schedules, legal restrictions, and project facts, and remember that crypto assets are speculative and losses can be substantial or total.

Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (2)

Vague Triggers

Medium
Confidence
92% confidence
Finding
The auto-trigger conditions are broad enough to activate on many generic crypto or token-related queries, which can cause the agent to inject investment-evaluation guidance without clear user intent. In a financial context, unintended activation increases the chance of unsolicited quasi-advisory output and can bias user decisions in a high-risk domain.

Missing User Warnings

Medium
Confidence
95% confidence
Finding
The skill recommends concrete participation actions like buying tokens, waiting for unlocks, testing for airdrops, and entering after price drops, but it does not prominently warn that these are speculative activities that can lead to substantial loss. In a retail-investing skill, omission of explicit risk disclosure can mislead users into treating the framework as safe or suitable financial guidance.

Static analysis

No suspicious patterns detected.