Back to skill

Security audit

城市更新改造现场分析

Security checks for vulnerabilities and agentic risk

Overview

This is a markdown-only urban-renewal photo analysis skill with no code execution, credential access, persistence, or hidden data flow.

Installers should only use this with site photos they are comfortable having analyzed. Treat any structural, safety, or demolition recommendations as preliminary observations that require qualified professional review before real-world decisions.

Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (1)

Vague Triggers

Medium
Confidence
86% confidence
Finding
The trigger list is broad enough to match ordinary discussion about redesigning a place or generating prompts, which can cause the skill to activate outside its intended scope. Over-broad activation is dangerous because it can hijack unrelated conversations or image-analysis requests and force a rigid workflow that may be inappropriate for the user's real intent.

Static analysis

No suspicious patterns detected.