Back to skill

Security audit

Swot Analysis

Security checks for vulnerabilities and agentic risk

Overview

This is a user-guided SWOT analysis skill with no executable artifact, credential use, persistence, or hidden data movement identified.

Review whether a Chinese-language SWOT workflow and user-provided business/project inputs fit your use case. The package appears security-benign, but its referenced helper files for templates and report generation are absent from the inspected artifact, so output automation may not work as described unless those files are supplied elsewhere.

Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Findings (1)

Natural-Language Policy Violations

Medium
Confidence
94% confidence
Finding
The skill metadata and body are written in Chinese and implicitly steer the interaction/output toward Chinese without asking the user for language preference. This can reduce user autonomy, cause misunderstanding, and create accessibility/usability issues for users who expect another language, though it does not introduce direct code-execution or data-exfiltration risk.

Static analysis

No suspicious patterns detected.