Back to skill

Security audit

quick research for VC/Consulting/Strategy Intern

Security checks for vulnerabilities and agentic risk

Overview

This is a research-formatting skill that guides public desk research and does not request code execution, persistence, credentials, or privileged access.

Install this if you want a structured desk-research workflow. Be aware that part of the guidance is written in Chinese and may steer some case-summary wording toward Chinese labels unless you ask the agent to use another language.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Findings (3)

Anti-Refusal Statement

High
Category
Anti-Refusal
Content
- For each promising case, collect at least 3 website evidence snippets (feature/pricing/use-flow)
- Add at least 1 metric anchor from trusted dataset (revenue/MRR/growth)
- Include at least 1 risk point and 1 falsification condition
- Do not submit if any case is only descriptive without judgment
Confidence
80% confidence
Finding
Skill instructs the agent to omit warnings, disclaimers, or ethical commentary. Stripping safety caveats hides risk from the user and is a common jailbreak preamble.

Natural-Language Policy Violations

Low
Confidence
82% confidence
Finding
The title and entire document are written in Chinese, and there is no indication that users may choose another language or locale. Under the stated policy, forcing a specific language without user opt-in can be a natural-language policy violation unless the locale constraint is documented and justified.

Natural-Language Policy Violations

Low
Confidence
92% confidence
Finding
Line L20 requires the final summary paragraph to use Chinese labels '(做什么/用户是谁/商业模式/为什么付费)'. This imposes a specific language/locale convention in the skill text without offering user opt-in or explaining why Chinese is required, which fits the language-policy violation category.

Static analysis

No suspicious patterns detected.