Back to skill

Security audit

Idea to Prompt

Security checks for vulnerabilities and agentic risk

Overview

This is a text-only skill for turning messy ideas into structured prompts, with no evidence of hidden execution, data access, persistence, or destructive behavior.

Before installing, consider that this skill may activate on broad requests to organize thoughts and will likely respond in Chinese unless adapted; users who want narrower activation should tighten the trigger phrases.

Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (3)

Vague Triggers

Medium
Confidence
88% confidence
Finding
The trigger phrases include very common conversational language such as '帮我整理一下' and '我想说的是', plus a broad semantic condition of any 'clearly unstructured brainstorming' input. This can cause the skill to activate when the user did not intend prompt restructuring, potentially overriding a more appropriate skill or altering the assistant's behavior unexpectedly. In this skill's context, the effect is limited because the skill only reformats user intent rather than executing actions, so the main risk is misrouting and confusion rather than direct compromise.

Vague Triggers

Medium
Confidence
90% confidence
Finding
The activation description uses broad trigger phrases such as '帮我整理一下' and also triggers on generally unstructured brainstorming. This can cause the skill to activate on ordinary conversation and reroute user intent into prompt-rewriting behavior, creating inappropriate tool invocation and response confusion rather than direct harm. The skill context makes this somewhat more dangerous because it is designed for many domains, including coding and planning, so over-activation could interfere with unrelated tasks.

Natural-Language Policy Violations

Medium
Confidence
88% confidence
Finding
The skill instructions are entirely in Chinese and do not provide a language choice or fallback behavior. This can lead to unexpected activation or opaque outputs for non-Chinese users, reducing transparency and user control; however, it is primarily a usability and misrouting risk rather than a direct security exploit. The context makes it less dangerous because the skill performs text structuring, not privileged actions, but it still increases the chance of user misunderstanding.

Static analysis

No suspicious patterns detected.