Back to skill

Security audit

可靠性设计技能

Security checks for vulnerabilities and agentic risk

Overview

This is a Chinese-language reliability-design reference skill made of static documentation, with no code, network access, credential handling, persistence, or destructive behavior found.

Install this if you want Chinese-language reliability design and FMEA guidance. Be aware that some referenced resources are empty or missing, so parts of the skill may be incomplete, but the inspected package does not request sensitive access or perform actions on your system.

Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Findings (2)

Natural-Language Policy Violations

Low
Confidence
95% confidence
Finding
This markdown file contains user-facing instructional content only in Chinese, and there is no indication that the user can choose another language or that the locale restriction is intentional. Under the policy rule for natural-language violations, forcing a specific language without user opt-in is a reportable issue.

Natural-Language Policy Violations

Medium
Confidence
93% confidence
Finding
该文件从标题到全文均以中文编写,没有任何说明这是面向特定中文用户群体的区域性资料,也未提供语言选择或用户自愿选择中文的机制。根据语言/区域策略,未经用户选择而强制单一语言属于自然语言层面的政策风险。

Static analysis

No suspicious patterns detected.