Back to skill

Security audit

翻译术语对照表-BWC

Security checks for vulnerabilities and agentic risk

Overview

This is a BWC-focused translation skill with some routing and terminology caveats, but it does not request sensitive access or perform unsafe actions.

Install only if you want BWC-specific English/Chinese technical translation rules. Review the broad triggers if your environment routes skills automatically, and populate or validate the glossary before using it for production, legal, or brand-sensitive documents.

Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (3)

Vague Triggers

Medium
Confidence
94% confidence
Finding
The manifest description includes broad trigger terms like "translate" and "翻译," which can cause this skill to activate for generic translation requests rather than only BWC-specific content. Over-broad routing can misapply domain-specific terminology and transformation rules to unrelated user content, leading to incorrect outputs and unsafe skill selection behavior.

Natural-Language Policy Violations

Medium
Confidence
87% confidence
Finding
The skill hard-codes translation of the acronym "BWC" to specific full-text equivalents in Chinese and English without checking user intent or established source terminology. This can silently alter product identity, create mistranslations in contexts where the acronym should remain unchanged, and propagate incorrect terminology across technical or legal documentation.

Vague Triggers

Medium
Confidence
94% confidence
Finding
The trigger list includes generic terms such as "translate" and "翻译", which are common in many unrelated user requests and can cause the skill to activate outside its intended BWC-specific scope. Overbroad invocation increases the chance that domain-specific translation rules or terminology constraints are applied to the wrong content, leading to unintended behavior, misrouting, or prompt-scope interference.

Static analysis

No suspicious patterns detected.