Back to skill

Security audit

蛋糕烘焙培训老师

Security checks for vulnerabilities and agentic risk

Overview

This is a disclosed cake-baking tutor that generates local HTML teaching reports, with only minor scope and activation cautions.

Install this if you want a Chinese-language cake baking assistant that may generate local HTML reports. Keep reports in a normal output folder, be aware it may activate on broad cake-related phrases, and treat any web-search supplement as untrusted unless you explicitly asked for current outside information.

Vulnerability Patterns
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
Findings (3)

Context-Inappropriate Capability

Low
Confidence
71% confidence
Finding
The workflow authorizes '联网搜索补充' even though the skill is primarily a local cake-teaching assistant and the manifest does not clearly justify network use. Unnecessary search/network expansion increases the chance of data leakage, prompt injection from remote content, or unexpected external dependencies in a context where users would not reasonably expect them.

Vague Triggers

Medium
Confidence
86% confidence
Finding
The trigger set includes many common baking phrases, making accidental invocation likely during ordinary conversation. Over-broad activation is risky because it can cause unsolicited behavior such as generating reports or steering the interaction into the skill's workflow without a clear opt-in from the user.

Vague Triggers

Medium
Confidence
89% confidence
Finding
The dedicated trigger list contains short and ambiguous terms like cake categories and baking topics that are likely to appear in normal user messages. In this skill, the danger is amplified because activation can transition directly into scripted workflows and file-generation instructions, increasing the chance of unintentional tool use.

Static analysis

No suspicious patterns detected.