Back to skill

Security audit

技术主管 任务拆分与调度

Security checks for vulnerabilities and agentic risk

Overview

This skill appears to be a non-executable technical-lead planning aid, with no evidence of hidden code, data access, persistence, or exfiltration.

Before installing, expect this skill to influence how an agent plans, decomposes, and routes technical work. If you use many specialist skills, review its trigger wording so it does not activate for routine planning prompts where a narrower specialist would be better.

Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (1)

Vague Triggers

Medium
Confidence
85% confidence
Finding
The invocation triggers are overly broad and include common coordination terms such as plan, assign, coordinate, and schedule. In an agent system, this can cause the skill to activate for many ordinary requests, leading to misrouting, unintended authority over unrelated tasks, and increased chance of bypassing more appropriate specialist skills.

Static analysis

No suspicious patterns detected.