Back to skill

Security audit

标书合规性审查

Security checks for vulnerabilities and agentic risk

Overview

The skill appears to do what it claims: process user-provided bid and tender files through a disclosed cloud API with clear credential, billing, and data-retention warnings.

Install only if you are comfortable sending bid/tender documents, proposal drafts, and related business data to the 百炼®标书 cloud service under your API-key account. Keep the API key out of chat, store it only in the local config file, confirm you have authority to upload all files, and note that proposal generation may consume account word credits while server-side results may persist briefly.

Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (1)

Vague Triggers

Medium
Confidence
82% confidence
Finding
The description and trigger language are extremely broad and include generic requests such as '帮我写投标书', '检查标书有没有问题', and related phrasing that could match loosely adjacent conversations. In agent environments, over-broad activation can cause unintended invocation on sensitive documents, increasing the chance of unnecessary cloud upload of bid/tender files and accidental processing outside the user's precise intent.

Static analysis

No suspicious patterns detected.