Back to skill

Security audit

绩效评估

Security checks for vulnerabilities and agentic risk

Overview

This is a simple Chinese performance-review helper that asks for business context and produces HR-style analysis, with no code execution or hidden access.

Use this as decision support for performance reviews and OKR analysis, but avoid pasting unnecessary employee records, compensation details, or confidential business data. Have HR or an appropriate reviewer validate outputs before using them in real evaluation or calibration decisions.

Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep

Static analysis

No suspicious patterns detected.