Back to skill

Security audit

产业-产业机会识别

Security checks for vulnerabilities and agentic risk

Overview

This is a disclosed Chinese industry-research skill that uses public web-based analysis to produce industrial opportunity reports, with no executable code, persistence, credential access, or destructive behavior found.

Before installing, expect the skill to run web-driven industry and policy research and produce strategic planning recommendations in Chinese. Users should verify cited sources and treat investment or industrial-planning conclusions as decision support rather than guaranteed forecasts.

Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (2)

Vague Triggers

Medium
Confidence
88% confidence
Finding
The trigger phrases are very broad and overlap with many general economic, planning, investment, and policy questions, which can cause the skill to activate outside a narrowly intended scope. Over-broad activation can override more appropriate skills or system behavior, leading to misleading outputs, unnecessary tool use, and expanded exposure to prompt-injection or data-quality risks from web-driven analysis.

Natural-Language Policy Violations

Medium
Confidence
81% confidence
Finding
The skill description and triggers are entirely in Chinese and strongly bias interaction toward Chinese without any stated language negotiation or fallback. This can cause the agent to respond in a language the user did not request, reducing usability and increasing the chance of misunderstanding in policy, investment, or planning advice contexts.

Static analysis

No suspicious patterns detected.