Back to skill

Security audit

供应商档案整理技能

Security checks for vulnerabilities and agentic risk

Overview

This skill organizes user-provided supplier documents into local archive files, with no evidence of hidden network access, credential use, or destructive behavior.

Install only if you are authorized to process the supplier records you provide. Store generated archives in an access-controlled folder, avoid unnecessary sensitive data, and delete local outputs when they are no longer needed.

Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Findings (2)

Missing User Warnings

Medium
Confidence
95% confidence
Finding
The skill is explicitly designed to ingest and structure supplier records that commonly contain sensitive business and personal data, including contact details, certification numbers, audit history, and quality metrics, but it provides no privacy, confidentiality, retention, or handling warning. This increases the chance that users will upload regulated or confidential documents without understanding the local processing and persistence implications.

Missing User Warnings

Low
Confidence
92% confidence
Finding
The skill instructs saving generated supplier archive files into the current working directory without warning that files will be created and remain on disk. Because the output contains consolidated supplier information, silent local persistence can expose sensitive data to other users, backup systems, source-control inclusion, or later unintended reuse.

Static analysis

No suspicious patterns detected.