Back to skill

Security audit

BI看板视觉交付标准

Security checks for vulnerabilities and agentic risk

Overview

This is a Markdown-only visual formatting guide; it may strongly steer document style, but it does not request risky access or hidden actions.

Install this if you want a strict Morandi business visual standard for reports, dashboards, and similar deliverables. For English, multilingual, branded, or non-procurement work, tell the agent to preserve the target language and brand rules so this skill does not overrule them stylistically.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (5)

Vague Triggers

Medium
Confidence
92% confidence
Finding
The skill description applies to nearly any client-facing deliverable across many formats, which can cause the agent to invoke it for broadly generic document tasks beyond the user's specific intent. Over-broad activation can override more appropriate task-specific skills and lead to unwanted formatting constraints or altered outputs, especially in workflows involving reports, dashboards, HTML, or spreadsheets.

Natural-Language Policy Violations

Medium
Confidence
85% confidence
Finding
The skill is written entirely in Chinese and implicitly imposes Chinese-language conventions without stating any language-preservation rule or requiring user consent. In multilingual environments, this can cause outputs, labels, or formatting guidance to drift from the user's requested locale, reducing usability and potentially introducing compliance or client-facing quality issues.

Vague Triggers

Medium
Confidence
88% confidence
Finding
The 'When to Use' section is expansive and ambiguous, including almost any external-facing deliverable or any request for polished, consistent output. This increases the chance of unintended invocation, which can steer agent behavior in ways the user did not request and create prompt-scope interference with other skills or domain-specific instructions.

Natural-Language Policy Violations

Low
Confidence
86% confidence
Finding
该文件包含自然语言与样式层面的语言/地区约束:`中文 PingFang SC / Microsoft YaHei` 被直接规定为默认字体栈,但未说明仅适用于中文交付物,或在非中文/多语言场景下如何选择。根据规则,若技能强制特定语言/locale 而无用户选择或合理限定,属于自然语言政策风险。

Natural-Language Policy Violations

Low
Confidence
78% confidence
Finding
The markdown instructs users to copy a prompt that the AI must 'strictly follow', and all instructions are written solely in Chinese with no opt-in or alternative language option. Under the policy for natural-language violations, fixed language or locale constraints should either offer user choice or be clearly justified as region-specific.

Static analysis

No suspicious patterns detected.