Back to skill

Security audit

小游戏5分钟报告

Security checks for vulnerabilities and agentic risk

Overview

This skill is a coherent report generator, but it needs Review because it can create and send Feishu documents without saying who receives them or requiring final approval.

Install only if you are comfortable giving the agent Feishu document creation and messaging authority. Before running it, specify the exact Feishu account, document location, recipient, and require a preview plus explicit approval before any message is sent.

Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Findings (1)

Missing User Warnings

Medium
Confidence
90% confidence
Finding
The skill explicitly describes creating a Feishu document and sending it via direct message, but provides no user-facing consent, review, or destination validation step before external delivery. This creates a real data-exfiltration and unintended-disclosure risk, especially because the generated report may contain scraped content, proprietary analysis, or sensitive business intelligence that users may not expect to be transmitted automatically.

Static analysis

No suspicious patterns detected.