Back to skill

Security audit

Overseas Expansion Framework

Security checks across malware telemetry and agentic risk

Overview

This is a content-only business strategy skill for choosing an international expansion mode, with no executable behavior or sensitive data access.

Installers should treat this as strategic guidance, not legal, tax, regulatory, or market-entry advice; regulated industries and local entity decisions should still be checked with qualified local counsel.

Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (2)

Vague Triggers

Medium
Confidence
92% confidence
Finding
The description says to activate when the user says 'we want to go global,' which is a broad natural-language phrase that could arise in many casual or high-level discussions. Although some additional constraints are provided, this trigger wording still risks unintended invocation because it is not narrowly scoped to a specific skill command or bounded context.

Natural-Language Policy Violations

Low
Confidence
79% confidence
Finding
The overview presents the concept as 'Spirit Expansion (精神出海)' using a specific non-English term inline, without offering any language or locale preference. While not severe, this can conflict with a language-choice policy if the skill assumes terminology from a particular language context without user opt-in or explanation of locale relevance.

VirusTotal

64/64 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.