Back to skill

Security audit

明歌内训课内容加工

Security checks for vulnerabilities and agentic risk

Overview

This instruction-only skill is coherent and disclosed: it processes a user-provided Feishu course document and creates four derived Feishu documents, but users should understand it writes persistent workspace content.

Install only if you are comfortable granting the Feishu connector access to the provided course document and allowing it to create four persistent child documents. Check source and destination sharing permissions first, avoid running it on confidential or personal data unless authorized, and review generated persuasion-oriented recommendations before sharing or using them.

Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (6)

Vague Triggers

Medium
Confidence
90% confidence
Finding
The example trigger phrases are broad natural-language commands such as '帮我总结' and '开始加工', which can plausibly appear in ordinary conversation and unintentionally invoke the skill when a Feishu link is present. In this skill, accidental activation is more dangerous because invocation causes bulk reading of course materials and automatic generation/archival of multiple documents, creating unnecessary data exposure and unintended writes.

Missing User Warnings

Medium
Confidence
95% confidence
Finding
The README states that the skill reads participant data, comments, and transcripts from a Feishu document and automatically creates archived output documents, but it does not clearly warn users about these access and write operations. Because the processed material may include internal training content, participant information, and sensitive discussion data, missing transparency increases the risk of users triggering data handling they did not fully understand or authorize.

Missing User Warnings

Medium
Confidence
95% confidence
Finding
The skill instructs the agent to read participant lists, timestamped comments, and full transcripts from a Feishu document, then generate and write four derivative documents, but it does not require any explicit user-facing notice or confirmation about accessing potentially sensitive personal/workspace data and creating new artifacts. This creates a privacy and integrity risk because users may trigger broad data processing and side effects without understanding that the workflow will read personal information and modify the workspace.

Missing User Warnings

Medium
Confidence
98% confidence
Finding
This section contains explicit instructions to create four Feishu wiki child nodes and write full generated content into them, yet there is no accompanying guardrail requiring user confirmation, preview, or warning that workspace data will be modified. The danger is heightened because the writes are automatic and repeated, so a casual trigger phrase plus link can cause unintended document creation, data duplication, and potential oversharing of sensitive meeting content.

Ssd 4

Medium
Confidence
93% confidence
Finding
This section presents a staged persuasion model that explicitly aims to move users from comprehension to emotional arousal, desire, impulse, and decision while reducing resistance. In the context of an agent skill that processes training content, embedding an operational framework for fear, reward, and objection handling can facilitate manipulative output generation rather than neutral summarization.

Ssd 4

Medium
Confidence
95% confidence
Finding
These sections explicitly coordinate emotional triggering, habit formation, reward design, and fear-of-loss reduction as tactics to shape audience behavior. Because the surrounding skill is used to transform course material into polished derivative documents, this content can cause the agent to generate manipulative messaging optimized to bypass deliberation and increase compliance.

Static analysis

No suspicious patterns detected.