Back to skill

Security audit

应急方案技能

Security checks for vulnerabilities and agentic risk

Overview

This is a document-template skill for creating emergency plans, with no executable code, network use, credential handling, or hidden install behavior found.

This skill appears safe to install for drafting emergency-plan documents. Users should still treat generated emergency guidance as a planning aid, verify legal and operational requirements locally, and have life-safety procedures reviewed by qualified personnel before use.

Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (1)

Vague Triggers

Medium
Confidence
87% confidence
Finding
The trigger condition uses open-ended wording such as “等场景”, which makes activation boundaries imprecise and can cause the skill to be invoked for loosely related requests. In this skill’s context, that mainly creates routing and policy-scope ambiguity rather than direct code-execution or data-exfiltration risk, but it can still increase the chance of inappropriate use for sensitive emergency or safety-related guidance.

Static analysis

No suspicious patterns detected.