Back to skill

Security audit

Eq Polisher

Security checks for vulnerabilities and agentic risk

Overview

This skill is a disclosed Chinese communication-polishing helper with no executable code, persistence, credential handling, or hidden data access.

Install this if you want a Chinese-language helper for softer, more tactful replies. Be aware it may activate on broad 'how should I reply' phrasing, so use explicit prompts when you want a different skill or a non-EQ answer.

Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (2)

Vague Triggers

Medium
Confidence
95% confidence
Finding
The trigger phrases are broad and include highly common expressions like '怎么回' and '帮我想想怎么回', which can cause the skill to activate for many unrelated conversations. This creates scope hijacking risk: the agent may route general requests into this skill and produce tone-polishing output when the user intended another capability, degrading safety, accuracy, and task routing.

Vague Triggers

Medium
Confidence
93% confidence
Finding
The fallback inference rules rely on vague heuristics like first-person vs. third-person phrasing and broad scene descriptions, without firm boundaries or disambiguation checks. An attacker or ordinary user can easily craft ambiguous input that gets misclassified into this skill, causing unintended handling of content and interfering with correct skill selection.

Static analysis

No suspicious patterns detected.