Back to skill

Security audit

科研人员学术品牌构建助手

Security checks for vulnerabilities and agentic risk

Overview

This skill is an advisory academic branding guide with no evidence of hidden execution, credential access, network activity, or persistence.

Reasonable to install from a security standpoint. Treat it as strategic advice, avoid sharing unpublished research, confidential partnership details, or account credentials in prompts, and re-review future versions if they add real scripts, platform integrations, API keys, or automated posting.

Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (2)

Vague Triggers

Medium
Confidence
81% confidence
Finding
The trigger list is broad enough to match ordinary academic or career conversations, which can cause unintended invocation of the skill outside the user's actual intent. Over-broad activation can lead to context hijacking, irrelevant guidance, and unintended processing of user content, especially in systems where skill routing affects what instructions or tools are loaded.

Vague Triggers

Medium
Confidence
84% confidence
Finding
The activation description says the skill triggers when users need influence building, branding, industry matching, or scholar-to-expert transition help, but it does not define boundaries for nearby topics it should ignore. This ambiguity increases the chance that the skill is selected for general academic, career, or research questions where its guidance may override more appropriate skills or instructions.

Static analysis

No suspicious patterns detected.