Back to skill

Security audit

二手电脑估价与出售物料生成器

Security checks for vulnerabilities and agentic risk

Overview

This skill is a disclosed Windows PC resale helper that reads local hardware details to estimate second-hand value and generate sale materials.

Before installing, understand that using the skill may run Windows PowerShell commands to inventory your PC hardware and attached devices, then store that information in local report files. Use it on your own computer, review the generated listing for any device details you do not want to publish, and follow its advice to wipe personal data before selling the machine.

Vulnerability Patterns
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
Findings (2)

Context-Inappropriate Capability

Low
Confidence
87% confidence
Finding
The skill collects peripheral, network adapter, camera, audio endpoint, and sound device details in addition to core valuation-relevant hardware. While not overtly malicious, this exceeds the minimum data needed for pricing and can reveal unnecessary local device inventory that may expose privacy-sensitive environment details.

Missing User Warnings

Medium
Confidence
95% confidence
Finding
The workflow defaults to automatic full-machine detection and instructs collection of extensive hardware and peripheral data without a prominent upfront consent step describing scope. This creates a privacy issue because users may trigger a valuation request expecting a price estimate, not broad local inventory of attached devices and system characteristics.

Static analysis

No suspicious patterns detected.