Back to skill

Security audit

Chudaxia Ai Coach Tools Position Agent Prompts Generator

Security checks for vulnerabilities and agentic risk

Overview

This is a Markdown-only skill for turning job descriptions into structured AI-agent prompts, with no hidden execution or persistence found.

Install this if you want help generating role-based system prompts from job descriptions. Before use, confirm which knowledge base the agent may search and review the generated prompt before deploying it, especially inferred responsibilities, permissions, compliance limits, and any internal information that should not be generalized into a reusable prompt.

Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (1)

Vague Triggers

Medium
Confidence
92% confidence
Finding
The skill description triggers on very broad phrases such as job descriptions,岗位职责, prompt generation, and AI Agent prompts, without narrowing by user intent, source constraints, or confirmation requirements. This can cause the skill to activate for unrelated or only partially related requests, increasing the chance of unintended document retrieval, prompt injection exposure from external knowledge sources, or inappropriate transformation of sensitive enterprise role materials.

Static analysis

No suspicious patterns detected.