Back to skill

Security audit

AI产品经理全流程助手

Security checks for vulnerabilities and agentic risk

Overview

This is a Chinese AI product-management helper with broad activation wording but no evidence of hidden, destructive, persistent, or credential-seeking behavior.

Install this if you want a Chinese-language AI product-management workflow assistant. Review or narrow the activation phrases if your agent auto-loads skills, and avoid using the chain-of-thought prompt example verbatim; ask for concise rationale instead.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
Findings (9)

Tp4

High
Category
MCP Tool Poisoning
Confidence
97% confidence
Finding

The declared description presents a broad AI product manager workflow assistant with multiple product strategy and design capabilities. The supplied code, however, only implements cost estimation for model usage based on DAU, calls, token counts, and predefined model pricing. It does not perform any of the core described functions such as requirements analysis, competitor analysis, PRD creation, AI feature design, RAG/Agent orchestration, or evaluation workflows. While cost estimation could be tangentially useful to AI product planning, it is a materially narrower and different primary purpose than the declared skill, so this is a clear description-behavior mismatch.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
95% confidence
Finding

The declared description presents a broad, intelligent end-to-end AI product manager assistant with analytical and design capabilities across multiple product phases. However, the supplied code only defines a static PRD markdown template and fills it with provided values. While the template includes sections labeled for AI models, prompt strategy, RAG, agent workflow, evaluation, competitors, and risks, the code does not actually generate, analyze, assess, or optimize any of those areas—it merely outputs placeholders or user-supplied content. Therefore, the actual behavior is materially narrower than the declared purpose, making this a clear description-behavior mismatch.

Content

No source excerpt is available for this finding.

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
70% confidence
Finding

Without declared permissions the skill's intent is opaque and cannot be validated.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

Several trigger phrases are common workplace requests such as writing a PRD, doing competitor analysis, or analyzing requirements, so the skill may capture routine conversations far outside its intended niche. In an agent environment, that can lead to prompt hijacking of general tasks, unexpected behavior substitution, and increased exposure to downstream tool use if the host system auto-invokes skills.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The skill states that it will activate for essentially any AI product management task and includes broad automatic matching behavior. Overly broad triggers increase the chance of accidental invocation in unrelated contexts, causing unrequested workflow steering, inappropriate prompt injection into normal conversations, or use in situations where the skill's assumptions are unsafe or irrelevant.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The prompt template explicitly instructs the model to reveal its step-by-step reasoning in a public-facing output. Exposing chain-of-thought can leak hidden reasoning, sensitive intermediate inferences, policy-related heuristics, or prompt-injection handling logic, and it is generally unnecessary for end users to receive safe, useful answers.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

This Python skill uses Chinese-only natural-language text in its module docstring, comments, usage instructions, and printed reports. Because the skill does not offer a language choice or document a justified region-specific constraint, it violates the policy against forcing a specific language without user opt-in.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

This file embeds all user-facing content, headings, and default values in Chinese, including the module description and generated PRD template. Under the policy, forcing a specific language without offering a user choice or documenting a justified regional scope is a natural-language policy violation.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
95% confidence
Finding

This markdown file contains user-facing instructional content exclusively in Chinese, and nowhere indicates that the language is optional or limited to a China-specific audience. Under the policy for natural-language violations, forcing a specific language without user opt-in can be a locale-policy issue.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.