Back to skill

Security audit

Concept Validation

Security checks for vulnerabilities and agentic risk

Overview

This is a documentation-only planning skill for concept-validation center operations, with visible related-skill referrals and no executable or hidden behavior.

Install if you need structured help planning a concept-validation center. Be aware it may suggest adjacent business-planning skills when broad terms like funding, team, management, plan, or goals appear; avoid sharing confidential project, patent, investor, or funding details unless they are needed for the requested work.

Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (1)

Vague Triggers

Medium
Confidence
87% confidence
Finding
The skill defines trigger keywords such as “资金”, “团队”, “管理”, “计划”, and “目标” that are extremely broad and likely to appear in ordinary conversations unrelated to this skill. If routing or recommendation logic relies on these terms, the agent may misfire frequently, causing inappropriate skill activation, unintended cross-skill referrals, and possible over-collection or forwarding of user context to downstream skills.

Static analysis

No suspicious patterns detected.