Back to skill

Security audit

摆摊创业全流程助手

Security checks for vulnerabilities and agentic risk

Overview

This appears to be a disclosed business-planning skill, with only a minor risk that broad Chinese trigger terms may activate it in unrelated conversations.

This skill looks safe to install for users who want business-planning help. Be aware that broad terms like street stall or stall location may activate it more often than intended; users should confirm they actually want this skill's planning workflow before sharing business details.

Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (2)

Vague Triggers

Medium
Confidence
85% confidence
Finding
The trigger list includes generic everyday terms such as '出摊', '摊位', and '小吃摊', which can match normal conversation outside the intended skill context and cause unintended activation. In an agent environment, overbroad activation can route unrelated user input into this skill, increasing the chance of incorrect advice, context hijacking, or accidental execution of the skill workflow.

Vague Triggers

Medium
Confidence
88% confidence
Finding
The trigger list includes broad, common terms such as '摆摊', '地摊', '出摊', and '摊位', which can match ordinary conversation and cause unintended activation. Accidental invocation can expose user context to the skill unnecessarily and may cause the agent to start collecting business/planning details or invoking tools when the user did not intend to use this skill.

Static analysis

No suspicious patterns detected.