Back to skill

Security audit

内容爆款拆解师

Security checks for vulnerabilities and agentic risk

Overview

This text-only skill analyzes user-provided content links and can optionally share generated output to Feishu, which matches its stated purpose but carries normal privacy cautions.

Install only if you are comfortable with the agent fetching links you provide and using configured Feishu tools when you ask for Feishu output or run it from a Feishu context. Prefer public, non-sensitive links and verify the destination before requesting a push to a chat or document.

Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Findings (1)

Missing User Warnings

Medium
Confidence
90% confidence
Finding
The skill is designed to automatically fetch arbitrary user-supplied links and optionally push generated content to Feishu, but it does not require explicit user confirmation or provide a clear warning that external network access and third-party data transmission will occur. This can expose sensitive URLs, private document contents, or internal resources to external tools/services and increases the risk of unintended data exfiltration or SSRF-like behavior depending on the capabilities of the linked tools.

Static analysis

No suspicious patterns detected.