Back to skill

Security audit

Pm Workbench

Security checks for vulnerabilities and agentic risk

Overview

This is a content-only Chinese product-management assistant skill with broad activation terms but no code execution, credential access, persistence, or hidden data handling.

Install this if you want a Chinese-language PM assistant for PRDs, analysis, retrospectives, interviews, and growth planning. Be aware that broad keywords may make it engage in general PM conversations, so disable or narrow it if you only want it for explicit document-generation tasks.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (14)

Credential Access

High
Category
Privilege Escalation
Confidence
60% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · .gitignore (reported line 4)May include surrounding context.

text
.DS_Store
*.log
node_modules/
.env
.__pycache__/
*.pyc

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

The skill description and usage instructions are presented entirely in Chinese, with no indication that users may interact in other languages or choose a preferred locale. Under the policy, forcing a specific language without user opt-in is a natural-language policy violation unless the locale restriction is clearly documented and justified.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The skill description and metadata position this as a broad product-management assistant for many common tasks, which increases the chance of activation in ordinary conversations that merely mention PM-related topics. Overbroad activation is dangerous because it can unexpectedly inject the skill's instructions and role constraints into unrelated sessions, causing context hijacking or unintended behavior selection.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
97% confidence
Finding

The trigger list includes highly generic terms such as 'PM', '面试', '产品经理', and similar broad phrases that are common in normal conversation and do not reliably indicate a request for this specific skill. This can cause accidental activation, leading the agent to apply specialized instructions in contexts where the user did not ask for them, degrading reliability and potentially overriding safer or more appropriate defaults.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The template is entirely written in Chinese and its operational instructions assume Chinese output, but there is no documented locale constraint or user-consent mechanism. This can override user language expectations, reduce usability, and in multi-skill settings may cause the assistant to respond in an unintended language, creating reliability and policy-compliance issues rather than direct security compromise.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

The activation guidance is very broad (e.g., any request to make a growth plan, discuss bottlenecks, or design referral mechanics) without clear boundaries on what the skill should and should not handle. Overbroad triggering can cause the skill to engage in contexts where user intent is ambiguous, increasing the chance of inappropriate invocation, off-scope advice, or conflict with higher-priority instructions from other skills.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

The file's title, instructions, examples, and usage guidance all assume Chinese output and interaction, but there is no statement that this is a China-specific or Chinese-only skill, nor any opt-in for language preference. Under the policy, forcing a specific language without user choice is a natural-language policy concern.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The activation guidance includes broad trigger phrases such as '帮我模拟面试', '练一下产品设计题', and '我的面试要准备了', which can overlap with ordinary conversation and cause the skill to activate when the user did not explicitly request this specific PM interview-coaching capability. Over-broad activation increases the chance of unintended context capture, irrelevant guidance, or routing users into a specialized workflow without clear consent.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
94% confidence
Finding

This file is a markdown document, so natural-language policy checks apply. The content forces a specific language/locale for all readers, and there is no indication that Chinese is optional or that the skill is intentionally region-specific.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
94% confidence
Finding

This markdown file is entirely written in Chinese and provides no indication that users may choose another language. Under the policy criteria, forcing a specific language without opt-in can be a natural-language policy violation unless the locale constraint is explicitly documented and justified.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
90% confidence
Finding

This markdown file presents all instructional content in Chinese, which can amount to a language/locale policy issue if the organization expects skills not to force a language without user opt-in. There is no indication that the skill is region-specific or that users can choose an alternate language.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
91% confidence
Finding

The entire template is written as a prescriptive framework in Chinese, with no indication that users may choose another language or that the template is intended only for a Chinese-language context. Under the policy, language constraints should be optional or explicitly justified rather than implicitly imposed.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
95% confidence
Finding

This markdown file contains user-facing instructions and content exclusively in Chinese, starting with the title and continuing throughout the template. Under the policy, forcing a specific language without user opt-in can be a natural-language policy violation unless the locale restriction is explicitly justified, which is not present here.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
87% confidence
Finding

This markdown template forces a specific language/locale for all users through its natural-language content. The file does not provide an opt-in, alternative language option, or justification that it is intended only for a Chinese-language audience.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.