Back to skill

Security audit

企业投资价值评估

Security checks for vulnerabilities and agentic risk

Overview

This is a disclosed Chinese-language enterprise investment research report skill that uses public information and does not include executable code, hidden data access, persistence, or account-changing behavior.

Install this if you want a Chinese-language workflow for enterprise investment-value reports based on public information. Review the generated report's sources, assumptions, and uncertainty labels carefully, and do not rely on it alone for investment, legal, credit, or due-diligence decisions.

Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (3)

Vague Triggers

Medium
Confidence
91% confidence
Finding
The trigger description is broad enough to match many generic business-analysis requests, which can cause the skill to activate outside its intended niche. That creates a prompt-scope control weakness: users asking for general strategy, research, or risk analysis may be steered into investment-style workflows and outputs they did not request.

Vague Triggers

Medium
Confidence
94% confidence
Finding
The trigger list consists of high-level phrases like investment evaluation, growth assessment, and risk screening without clear boundaries, making accidental or overbroad invocation likely. In a multi-skill environment, this can hijack unrelated analytical tasks, reduce user control, and route sensitive business requests into a predefined workflow that may not fit the user's intent.

Vague Triggers

Medium
Confidence
88% confidence
Finding
The trigger set is very broad and consists of generic business-analysis phrases without clear activation boundaries, exclusions, or disambiguation criteria. In an agent environment, this can cause the skill to be invoked for loosely related requests, leading to unintended handling of sensitive investment, diligence, or partnership decisions and increasing the chance of inappropriate automation or overreach.

Static analysis

No suspicious patterns detected.