Back to skill

Security audit

Lanxin Media

Security checks for vulnerabilities and agentic risk

Overview

The skill is meant for Lanxin file and image sending, but its broad triggers and no-refusal instructions could cause unintended upload-style tags to be emitted.

Install only if you specifically want Lanxin media-sending tags enabled. Treat any <lximg> or <lxfile> output as a request to upload or transmit that path or URL, and confirm the file, destination, and sensitivity before use. The skill would be safer with narrower triggers and explicit confirmation before emitting send tags.

Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (1)

Vague Triggers

High
Confidence
95% confidence
Finding
The trigger list includes broad everyday terms like '图片', '文件', '文档', and '表格', which can cause the skill to activate in many unrelated conversations. In this skill, unintended activation is more dangerous because the instructions strongly force direct emission of file-send tags and suppress normal refusal or clarification behavior, increasing the chance of accidental file exfiltration or unsafe attachment handling.

Static analysis

No suspicious patterns detected.