Back to skill

Security audit

企业内账管理技能包

Security checks for vulnerabilities and agentic risk

Overview

This finance skill is only a Markdown guide, but it gives high-risk internal accounting guidance that normalizes private accounts, undocumented transactions, and dual-book differences for a listed company.

Install only after review by finance, legal, tax, or internal audit. Do not use this skill to manage or justify unreported income, undocumented expenses, kickbacks, private-card company flows, or differences between internal and statutory books; those should be treated as compliance exceptions requiring approved controls and documentation.

Vulnerability Patterns
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
Findings (5)

Context-Inappropriate Capability

Medium
Confidence
96% confidence
Finding
The skill explicitly documents use of personal bank cards, private accounts, and undocumented cash flows within a listed-company internal accounting workflow. In this context, that guidance can facilitate concealment of corporate transactions, evasion of internal controls, and bypass of regulated bookkeeping requirements, making the content materially dangerous rather than merely informational.

Context-Inappropriate Capability

High
Confidence
99% confidence
Finding
The skill normalizes recording non-invoiced transactions, kickbacks/commissions, and private reimbursements as part of routine internal accounting. For a listed-company setting, this enables books-and-records violations, bribery concealment, tax evasion, and fraudulent financial reporting, all of which can lead to severe legal and regulatory exposure.

Context-Inappropriate Capability

High
Confidence
98% confidence
Finding
The reconciliation section treats undocumented income, undocumented costs, kickbacks, and personal consumption as normal permanent differences between internal and external books. That framing legitimizes dual-book accounting and concealment of improper transactions, which is especially dangerous for a listed company subject to strict disclosure, audit, and anti-fraud obligations.

Vague Triggers

Medium
Confidence
86% confidence
Finding
The trigger list includes broad terms such as internal accounting, profit analysis, management reports, receivables/payables, and automation, which can cause the skill to activate in ordinary finance conversations outside the intended narrow use case. Because the skill contains risky guidance around undocumented transactions and private accounts, accidental invocation increases the chance that unsafe instructions are surfaced to users who did not seek them.

Missing User Warnings

Medium
Confidence
92% confidence
Finding
The skill processes highly sensitive financial, payroll, receivables/payables, and personal-account information without any warnings, handling restrictions, or compliance boundaries. In a corporate finance context, absence of such warnings materially raises the risk of exposing personal data, bank details, and confidential financial records, while also encouraging unsafe entry of noncompliant transactions.

Static analysis

No suspicious patterns detected.