Back to skill

Security audit

Industry Opportunity Radar / 行业机会雷达

Security checks for vulnerabilities and agentic risk

Overview

This skill is a disclosed JishuDB-based industry monitoring workflow that saves approved research snapshots and reports, with repeated approval and safety checks.

Before installing, confirm you are comfortable granting this skill scoped JishuDB write access for the selected knowledge base and allowing it to retain permitted source records, snapshots, and generated reports. Only enable recurrence if you explicitly approve the schedule, KB, output location, source scope, and notification destination.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Vulnerability Patterns
  • Memory PoisoningPersistent Context Injection, Context Window Stuffing, Memory Manipulation
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (1)

Memory Manipulation

High
Category
Memory Poisoning
Confidence
80% confidence
Finding

Skill manipulates agent memory, state, or stored context. Memory corruption can alter personality, override safety rules, or cause unpredictable behavior.

Content

Scanner excerpt · SKILL.md (reported line 229)May include surrounding context.

md
content; replay URL/preparation only with identical supported keys and
   arguments. After repair and approved retry, use
   `kb_retry_job({kbId, jobId})` for an existing failed/cancelled job. Never
   rotate identities, repeatedly import, delete history, or poll endlessly.
   Retain sanitized errors and non-secret recovery IDs.

### Recurrence is separate host automation

Static analysis

No suspicious patterns detected.