Back to skill

Security audit

Industry Scenario Generator

Security checks for vulnerabilities and agentic risk

Overview

This skill is a Chinese sales-content generator with no executable code, dependencies, persistence, or hidden high-impact behavior.

Install this if you want a Chinese-language sales scenario generator. Review generated claims before customer use, especially when it uses web search or references real cases, because the skill itself instructs the agent not to fabricate but does not provide built-in verification data.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (4)

Hidden Instructions

High
Category
Prompt Injection
Confidence
60% confidence
Finding

Hidden instructions were detected in comments or invisible text. These could contain malicious directives. Manual review is recommended.

Content

Scanner excerpt · SKILL.md (reported line 1)May include surrounding context.

md
---
name: industry-scenario-generator
description: >
  行业场景方案自动生成。输入行业+产品方向,自动输出行业痛点分析+典型场景用例+PPT素材MD+交流话术。

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

The trigger phrases are broad, natural-language requests that many normal user conversations could match, increasing the chance of unintended skill activation. In a sales-content generation skill, accidental activation can cause the agent to ignore user intent boundaries, inject irrelevant workflow behavior, or invoke downstream capabilities such as document generation when not explicitly desired.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
89% confidence
Finding

The manifest description and trigger definitions are entirely in Chinese and present the skill as operating in Chinese by default, with no indication that users may choose another language. This can violate language or locale policy when a skill implicitly constrains output language without opt-in.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
75% confidence
Finding

The manifest description is written entirely in Chinese, with no indication that other languages are supported or that language selection is optional. For an organizational language/locale policy review, this can be a concern because it implicitly constrains use to a specific language without documenting opt-in or justification.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.