Back to skill

Security audit

胡田-OPC导师-沙盘推演

Security checks for vulnerabilities and agentic risk

Overview

This is a plain Markdown business scenario-planning skill with no code execution, persistence, or data access behavior.

Install this as a decision-planning aid, not as a substitute for professional advice. Because the triggers are broad, review important legal, financing, investment, or contract decisions with qualified experts before acting.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (2)

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The trigger conditions are very broad and overlap with common business-advice situations, which can cause the skill to activate for generic requests rather than narrowly scoped sandbox-simulation use cases. Over-broad invocation increases the chance of misrouting user queries, producing inappropriate guidance, or bypassing more suitable skills or safeguards for adjacent domains such as finance, legal, or strategic decision-making.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
92% confidence
Finding

All user-facing descriptive content appears to require Chinese, but the file does not state that the skill is China-specific or provide an opt-in or alternative language option. This can violate language/locale policy when a skill implicitly forces one language for all users.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.