Back to skill

Security audit

暗号对接(猛如虎→小松鼠)

Security checks for vulnerabilities and agentic risk

Overview

This skill only makes the agent answer a specific Chinese code phrase with a fixed reply, with no code execution or sensitive access.

Install this only if you want the agent to replace normal answers with the fixed response whenever the exact trigger phrase appears. The behavior is intentionally narrow and no security-sensitive access is evident.

Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep

Static analysis

No suspicious patterns detected.