Back to skill

Security audit

OPC / 超级个体落地清单

Security checks for vulnerabilities and agentic risk

Overview

This is a Chinese-language Web3 freelancing checklist with clear safety boundaries and no executable code, persistence, or hidden data access.

Installers should understand this is a Chinese-language educational checklist about Web3-related individual work, not legal, tax, or investment advice. Users should be especially cautious with any real-world project involving tokens, fundraising, exchange activity, wallet custody, or promised appreciation, and should route those questions to qualified compliance review.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (4)

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

The manifest description explicitly states the skill is aimed at '中文 Web3 内容创作者、个体创业者、自由职业者', which imposes a language/locale constraint in natural language. The file does not offer users a language choice or explain that the constraint is required for a region-specific compliance purpose, so it matches the language-policy concern for this rule.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
89% confidence
Finding

The trigger tests use broad, example-based natural language such as '想进 Web3' and '不知道自己能接什么活' without clear, minimal activation boundaries. This can cause the skill router to over-trigger on adjacent topics like investing, community design, or compliance questions, increasing the chance of misrouting users into advice about tokenized work instead of safer or more appropriate skills.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
83% confidence
Finding

All user-facing prompts, expected behaviors, and notes are written in Chinese, and the file provides no indication that other languages are supported or that Chinese is a deliberate, documented locale constraint. Under the policy rule, forcing a specific language without user opt-in can be a locale-policy issue.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
95% confidence
Finding

This markdown file contains user-facing natural language exclusively in Chinese, but does not state that the skill is Chinese-only or offer any language/locale choice. Per the policy, forcing a specific language without opt-in can be a locale-policy violation.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.