Back to skill

Security audit

公务员考试备考指导

Security checks for vulnerabilities and agentic risk

Overview

This is a disclosed exam-prep guidance skill made of Markdown reference materials, with no executable code or hidden high-impact behavior found.

Installers should understand that the skill may activate on broad exam terms and may use web search for current-affairs questions. It does not ask for credentials, run code, or persist processes, so the main practical consideration is whether the broad triggers fit the user's workflow.

Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (2)

Vague Triggers

Medium
Confidence
85% confidence
Finding
The trigger list contains broad terms such as '行测', '申论', '复习计划', and '真题解析' without clear scoping to this specific skill, which can cause the skill to activate in unrelated conversations. While this is not a code-execution issue, unintended activation can surface the wrong skill, confuse users, and increase the chance that the agent applies exam-prep behavior outside the intended context.

Vague Triggers

Medium
Confidence
93% confidence
Finding
The trigger list is overly broad and includes generic terms like '国考', '省考', '行测', and '申论' that may appear in ordinary conversation, causing the skill to activate outside clearly intended contexts. This can lead to inappropriate interception of unrelated user requests, unnecessary web access or file loading, and reduced reliability of routing, even though the skill content itself is not inherently harmful.

Static analysis

No suspicious patterns detected.