Back to skill

Security audit

应用市场监测

Security checks for vulnerabilities and agentic risk

Overview

This skill automates read-only AppGallery lookups from a user-provided app list and generates a report, with the main caution being that its trigger can start a batch workflow quickly.

Install this if you want automated AppGallery monitoring reports. Use the dedicated keyword only when the attached spreadsheet is intended for this skill, since it may immediately parse the file, operate AppGallery through the phone GUI, and generate a PDF report.

Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (2)

Vague Triggers

Medium
Confidence
90% confidence
Finding
The listed trigger phrases include broad natural-language requests such as '查一下这些 App 的更新情况' and '帮我查应用市场的版本', which can plausibly appear in ordinary conversation and cause unintended activation of a high-effort GUI automation workflow. Because the skill reads attachments, navigates a marketplace app, and generates a report automatically, ambiguous invocation increases the chance of unauthorized or surprising actions being performed on user-provided data.

Vague Triggers

Medium
Confidence
95% confidence
Finding
The '应用市场监测' mode auto-runs the full workflow whenever that keyword appears with an Excel attachment, without requiring an explicit confirmation or validating that the attachment is actually intended for this skill. This creates an overly permissive trigger path where unrelated spreadsheets or incidental mentions can launch bulk data extraction, GUI actions, and document generation, increasing the risk of unintended processing and privacy issues.

Static analysis

No suspicious patterns detected.