Back to skill

Security audit

产学研资源对接助手

Security checks for vulnerabilities and agentic risk

Overview

This appears to be a commercialization resource-matching helper with broad triggers, but no evidence of hidden execution, credential use, persistence, or malicious behavior.

Use this skill when you intentionally want commercialization or resource-matching help. Avoid sharing confidential technical details, trade secrets, cap tables, customer lists, or unreleased business plans unless you are comfortable using them in that workflow.

Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (2)

Vague Triggers

Medium
Confidence
86% confidence
Finding
The trigger list is very broad and includes common terms like '企业合作', '投资机构', and '产业资源', which can cause the skill to activate during ordinary conversation rather than only when resource-matching help is actually needed. Over-triggering can lead to inappropriate context capture, irrelevant guidance, or unneeded collection and processing of commercially sensitive project details.

Vague Triggers

Medium
Confidence
84% confidence
Finding
The activation description says the skill triggers when users need partner, investor, incubator, or commercialization help, but it does not define boundaries for adjacent cases. In this context, ambiguity is more dangerous because the skill may encourage disclosure of confidential technical, business, or IP information in situations where the user only wanted general information rather than tailored matchmaking or commercialization assistance.

Static analysis

No suspicious patterns detected.