Back to skill

Security audit

德胧大佬蒸馏系统

Security checks for vulnerabilities and agentic risk

Overview

This skill is instruction-only, but it asks agents to build reusable profiles of real executives from internal Feishu messages, documents, colleague input, and decision records without clear consent or data-handling controls.

Install only in a controlled internal environment where the organization and the named individuals have authorized the specific Feishu sources to be used. Limit inputs to approved documents, avoid private chats and personnel-adjacent evaluations, keep the AI-simulation disclaimer visible, and do not share outputs publicly or treat them as real executive positions.

Vulnerability Patterns
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
Findings (3)

Context-Inappropriate Capability

Medium
Confidence
95% confidence
Finding
The `nuwa-delao` submodule materially expands the skill from opinion simulation into internal surveillance and profile construction by collecting Feishu messages, documents, and decision histories for named executives. That creates a reusable capability for aggregating private communications and behavioral profiles, which can expose sensitive internal data and enable unauthorized inference about individuals.

Intent-Code Divergence

Medium
Confidence
91% confidence
Finding
The skill claims not to handle sensitive personnel topics, yet elsewhere specifies ingestion of executives' private messages, colleague evaluations, and decision records into durable role cards. This policy-to-behavior mismatch is dangerous because users and operators may rely on stated boundaries while the implementation still normalizes collection and synthesis of sensitive personal and workplace information.

Ssd 3

High
Confidence
98% confidence
Finding
The skill explicitly instructs collection, distillation, and retention of private internal communications, colleague assessments, and decision records to build reusable executive profiles. In this context, that is especially dangerous because the system is framed as a scalable 'self-distillation engine,' making privacy-invasive profiling and sensitive corporate knowledge extraction operationalized rather than incidental.

Static analysis

No suspicious patterns detected.