Back to skill

Security audit

期刊论文重组深化

Security checks for vulnerabilities and agentic risk

Overview

This is an instruction-only academic paper workflow with disclosed literature search and Word-document output steps, and no evidence of hidden code or unsafe behavior.

Reasonable to install for academic paper restructuring. For unpublished or confidential work, avoid sending full manuscript text to external search services, review generated citations, and use a trusted document-generation tool for the final .docx file.

Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (2)

Vague Triggers

Medium
Confidence
86% confidence
Finding
The trigger phrase '帮我整理这篇论文' is broad everyday language that can activate this skill for loosely related requests, causing overbroad invocation and unexpected actions such as literature-collection workflows or document restructuring. In agent systems, ambiguous triggers can route user content into a more powerful workflow than intended, increasing the chance of unintended data handling or unauthorized tool use.

Vague Triggers

Medium
Confidence
84% confidence
Finding
The trigger '搜集文献' is under-scoped and may match generic research requests unrelated to paper reorganization, causing the skill to activate outside its intended domain. Because this skill can drive multi-phase processing and eventual document generation, vague routing increases the risk of unnecessary external retrieval and unintended handling of user material.

Static analysis

No suspicious patterns detected.