Back to skill

Security audit

概念验证 技术验证引擎

Security checks for vulnerabilities and agentic risk

Overview

This skill is a disclosed Chinese-language framework for technical concept validation and does not request unusual system access or hidden authority.

Install this if you want a Chinese-language assistant workflow for early-stage technical feasibility and TRL validation. Be aware it may activate for general technical validation questions, and responses are likely to follow the Chinese framework and terminology in the artifact.

Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (2)

Vague Triggers

Medium
Confidence
92% confidence
Finding
The trigger conditions are very broad and generic ('ask about technical feasibility', 'evaluate TRL', 'design validation plan', etc.), so the skill may activate in contexts where the user did not explicitly request this specific workflow. That can cause prompt/skill hijacking of unrelated conversations, override a more appropriate tool, or steer users into a fixed process without clear consent.

Natural-Language Policy Violations

Medium
Confidence
84% confidence
Finding
The skill metadata description is written entirely in Chinese and appears to bias behavior toward Chinese-language operation without an explicit user-language check. In multilingual environments this can lead to unexpected language switching, reduced transparency, and incorrect downstream handling if users expect responses in another language.

Static analysis

No suspicious patterns detected.