Ae1
- Category
- analysis-evasion
- Confidence
- 100% confidence
- Finding
Referenced artifact was not completely inspected
- Content
md [English](./SKILL.md) · [中文](./SKILL-cn.md)
Security audit
Security checks for vulnerabilities and agentic risk
This skill is a disclosed wrapper for a hosted dLazy chat agent, with expected external API use, credential storage, and optional file upload.
Install only if you intend to use dLazy's hosted service. Prompts, options, project/session metadata, and any files passed with --files may be sent to dLazy, and login stores an API key locally; use npx if you prefer not to keep a global CLI installed.
Referenced artifact was not completely inspected
[English](./SKILL.md) · [中文](./SKILL-cn.md)
该文件是 markdown,适用 SQP-1。列出的触发词如“对话”“和 agent 聊”“继续某个项目”都较为泛化,缺少明确边界、限定场景或反例说明,容易与普通聊天或一般任务请求重叠。
Large whitespace padding was detected (a block of blank lines or a long run of spaces). This can push injected instructions below or to the right of the visible area so a human reviewer never sees them while the agent still reads them. Manual review of the hidden content is recommended.
## 错误处理
| Code | 错误类型 | 示例信息 |
| ---- | -------------------------------- | ------------------------------------------------------------------------------------------------------------------------ |
| 401 | 未授权 (API Key缺失或无效) | `ok: false, code: "unauthorized", message: "API key is missing or invalid"` |
| 501 | 缺少必填参数 | `error: required option '--prompt <prompt>' not specified` |
The listed trigger phrases include generic terms like "chat," "talk to the agent," and "continue a project," which are broad enough to match ordinary user requests outside a narrow dlazy-specific context. The section does not provide exclusion conditions or negative examples to clarify when the skill should not activate.
Large whitespace padding was detected (a block of blank lines or a long run of spaces). This can push injected instructions below or to the right of the visible area so a human reviewer never sees them while the agent still reads them. Manual review of the hidden content is recommended.
## Error Handling
| Code | Error Type | Example Message |
| ---- | ---------------------------------- | ------------------------------------------------------------------------------------------------------------------------ |
| 401 | Unauthorized (No API Key) | `ok: false, code: "unauthorized", message: "API key is missing or invalid"` |
| 501 | Missing required parameter | `error: required option '--prompt <prompt>' not specified` |
该文件中的自然语言指令使用“您必须明确告知用户”等强制性中文输出表述,但未在这些指令处说明应按用户语言偏好回应。虽然文档顶部有英文链接,但这里的执行指令本身没有提供语言/locale 选择,可能与组织的语言选择政策冲突。
The description and title present mixed English and Chinese content, but the file does not state that the user can choose a preferred language or that the skill is intentionally bilingual. This can conflict with language/locale policy requirements where language choice should be explicit or opt-in.
No suspicious patterns detected.