Back to skill

Security audit

Ifeng

Security checks for vulnerabilities and agentic risk

Overview

This is an instruction-only skill for summarizing public Ifeng news pages, with no code execution, credentials, persistence, or hidden access.

This appears safe to install for lightweight summaries of publicly available Ifeng content. Use it only within the site’s rules, avoid bulk collection, and remember that VirusTotal telemetry was still pending rather than a negative signal.

Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep

Static analysis

No suspicious patterns detected.