Back to skill

Security audit

天台藏全集2026

Security checks for vulnerabilities and agentic risk

Overview

This skill is a narrowly scoped Tiantai Buddhist literature retrieval guide with no executable code, persistence, or hidden data handling.

Installers should treat this as a benign research helper, while noting that it may activate for broad Tiantai-related questions and depends on access to the named IMA knowledge base for best results.

Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (2)

Vague Triggers

Medium
Confidence
82% confidence
Finding
The description includes a broad trigger condition covering generic Tiantai-related questions and '天台典籍等', which can cause the skill to activate outside narrowly intended contexts. Over-broad activation is risky because it may intercept unrelated scholarly or religious queries and force use of a constrained single-source workflow, increasing the chance of inappropriate handling or response hijacking within the agent routing layer.

Natural-Language Policy Violations

Medium
Confidence
76% confidence
Finding
The instruction to use traditional Chinese search terms ('使用繁体中文') imposes a language choice without user opt-in. This is mainly a quality and accessibility issue, but it can also mis-handle user intent, degrade multilingual interactions, or cause the agent to override the user's requested language and search strategy.

Static analysis

No suspicious patterns detected.