Back to skill

Security audit

国企采购"三重一大"决策合规专家

Security checks across malware telemetry and agentic risk

Overview

This skill is a disclosed compliance-assistance skill that analyzes user-provided state-owned-enterprise procurement rules and does not include hidden execution, persistence, or data-exfiltration behavior.

Before installing, users should understand that this is an internal reference aid, not legal advice or a final compliance decision. Provide only the minimum needed procurement and governance information, redact enterprise names, supplier names, exact amounts, state secrets, core commercial secrets, and personal data, and verify legal citations and knowledge-base outputs with counsel or the relevant regulator before relying on them.

Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep

VirusTotal

63/63 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.