Back to skill

Security audit

Show Me The Money · 来财

Security checks for vulnerabilities and agentic risk

Overview

This is a disclosed entry page for a business-skills suite and does not itself run code, access data, or take actions beyond telling users how to install the full package.

Installers should treat this as a pointer to a larger GitHub-hosted skill pack. Before installing the full pack, review the repository contents and be especially attentive to any skills that automate ads, outreach, finance, memory, upgrades, or operations.

Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (1)

Vague Triggers

Medium
Confidence
92% confidence
Finding
The trigger phrases are broad and map to common, high-frequency requests such as starting a business or finding a business idea. This can cause the skill to activate in situations where the user did not intend to invoke this specific package, potentially steering users into installation flows or business automation guidance they did not explicitly request.

Static analysis

No suspicious patterns detected.