Back to skill

Security audit

PRD 文档生成器

Security checks for vulnerabilities and agentic risk

Overview

This skill is a straightforward PRD document generator with no executable code, hidden data access, or persistence beyond normal skill installation.

Install this if you want a Chinese-oriented structured PRD generator. Be aware it may activate on broad requirements-document requests, so review generated PRDs for scope and language fit before relying on them.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (3)

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The trigger phrases are broad enough to match many ordinary product or documentation requests, which can cause the skill to activate outside its intended scope. In an agent environment, over-broad activation increases the chance of unintended prompt injection exposure, user confusion, or the wrong automation being applied to unrelated tasks.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

The skill’s activation examples include very broad phrases such as generic requests to 'write a PRD' or 'generate a requirements document', which can cause the orchestrator to invoke this skill in situations where the user did not specifically want this structured PRD workflow. While this is not an exploit primitive by itself, over-broad triggering can lead to misrouting, unnecessary collection of business details, and generation of overly prescriptive artifacts in the wrong context.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
92% confidence
Finding

The natural-language description is written entirely in Chinese and presents the skill as a Chinese PRD generator, with no indication that users can choose another language or locale. This can violate language/locale policy when a skill appears to prescribe a specific language experience without explicit opt-in or justification.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.