Back to skill

Security audit

System Nine Elements

Security checks for vulnerabilities and agentic risk

Overview

This is a text-only Chinese system-analysis framework with no code execution, credential use, network access, or persistence.

Install it if you want a Chinese nine-element framework for system analysis. Review the activation phrases if you use many skills, because it may trigger on broad requests like system design or deep analysis.

Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (2)

Vague Triggers

Medium
Confidence
89% confidence
Finding
The activation phrases are broad and generic enough that the skill may trigger for many ordinary analysis requests, causing unintended routing or overriding a more appropriate skill. While this is not directly exploitable as code execution, it can degrade system behavior, produce irrelevant outputs, and increase the chance of prompt-conflict or policy-bypass interactions in multi-skill environments.

Natural-Language Policy Violations

Medium
Confidence
83% confidence
Finding
The skill is written to operate in Chinese without stating that it should adapt to the user's language, which can create usability and comprehension failures when invoked for non-Chinese users. In security-sensitive or high-stakes analytical contexts, language mismatch can cause misunderstanding of recommendations or conceal important limitations, though the direct security impact is limited.

Static analysis

No suspicious patterns detected.