Back to skill

Security audit

胡开奕 · 养老与传承顾问技能 · 会谈纪要整理

Security checks for vulnerabilities and agentic risk

Overview

This is a prompt-only meeting-notes skill for eldercare and inheritance advisory work, with sensitive inputs disclosed and no hidden execution, storage, or network behavior found.

Before installing, users should understand that this skill is meant for sensitive client advisory notes. Use it only with client permission, prefer anonymized or redacted inputs, and review any customer-facing follow-up message manually for privacy, legal, medical, insurance, and regulatory accuracy.

Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (2)

Vague Triggers

Medium
Confidence
89% confidence
Finding
The trigger list includes generic phrases such as '会谈纪要', '整理纪要', and '客户沟通纪要' that can overlap with ordinary note-taking or meeting-summary requests outside the intended insurance/wealth-management context. This increases the chance of accidental invocation on unrelated conversations, potentially causing sensitive user content to be routed into a skill that extracts health, family, financial, and inheritance-related data.

Missing User Warnings

Medium
Confidence
94% confidence
Finding
The manifest explicitly advertises processing of client recordings, chat logs, and free-form notes to derive structured summaries covering health, finances, housing, family relationships, and existing insurance. Because this is highly sensitive personal and potentially regulated information, the absence of any privacy notice, consent language, retention limits, or data-handling disclosure materially raises the risk of unauthorized collection, over-processing, and user surprise.

Static analysis

No suspicious patterns detected.