Back to skill

Security audit

张一鸣.skill - 字节跳动创始人思维操作系统

Security checks for vulnerabilities and agentic risk

Overview

This is a prompt-only persona skill that may activate broadly, but it does not request system access, credentials, code execution, persistence, or external data access.

Safe to install from a security perspective. Treat its replies as a stylized simulation based on public information, not statements from Zhang Yiming. Be aware that broad trigger phrases may switch the assistant into persona mode unexpectedly; use the documented exit phrases to return to normal behavior.

Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (2)

Vague Triggers

High
Confidence
97% confidence
Finding
The trigger conditions are extremely broad and include generic references like “一鸣”, “字节怎么看”, and “头条的逻辑”, which are likely to activate in ordinary conversation without clear user intent to invoke roleplay. This can cause unintended persona switching, override the assistant’s normal response style, and create downstream safety issues because the skill also instructs persistent in-character behavior once activated.

Natural-Language Policy Violations

Medium
Confidence
88% confidence
Finding
The skill mandates a specific persona, voice, and first-person identity without requiring fresh user consent at response time, and it suppresses repeated disclosure after the first activation. That increases the chance of confusing users about whether they are receiving normal assistant output or impersonation-style roleplay, especially in long conversations where the initial disclaimer may be forgotten.

Static analysis

No suspicious patterns detected.