Back to skill

Security audit

漂流瓶

Security checks for vulnerabilities and agentic risk

Overview

The skill appears to be a lightweight inspirational/random-message skill with no artifact-backed evidence of sensitive access or harmful behavior.

This looks acceptable to install if you want a random inspiration or drift-bottle style assistant behavior. Review the trigger wording first, because phrases like requests for inspiration or life reflections may activate it more often than expected.

Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (1)

Vague Triggers

Medium
Confidence
88% confidence
Finding
The trigger list includes broad phrases such as '随机消息', '获取灵感', and '人生感悟', which can overlap with ordinary user conversation and cause the skill to activate when the user did not explicitly ask for it. In an agent environment, overly broad activation can hijack unrelated interactions, leading to unintended script execution and confusing or policy-bypassing responses.

Static analysis

No suspicious patterns detected.