Back to skill

Security audit

博客/公众号文章润色改写专家

Security checks for vulnerabilities and agentic risk

Overview

This skill is an article-rewriting tool, but it asks the agent to use logged-in browser sessions and explicitly supports similarity reduction and AI-authorship masking without enough user-control boundaries.

Install only if you want an agent to fetch and rewrite articles you are authorized to use. Avoid private, paywalled, or logged-in pages unless you explicitly approve browser-session access, and follow copyright, attribution, and AI-disclosure rules before publishing rewritten content.

Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Findings (2)

Ssd 2

Medium
Confidence
98% confidence
Finding
The skill explicitly promotes deep rewriting to reduce similarity and remove AI traces while preserving meaning, which materially enables evasion of plagiarism, originality, and AI-authorship detection mechanisms. In context, this is not just style improvement; it operationalizes concealment of provenance and can facilitate academic, publishing, or platform policy abuse.

Ssd 2

Medium
Confidence
99% confidence
Finding
The dedicated '去 AI 化' rules provide concrete transformations for masking machine-generated authorship through stylistic substitutions, making the concealment behavior more actionable and repeatable. This increases misuse potential by turning detection evasion into an explicit feature rather than an incidental side effect of normal editing.

Static analysis

No suspicious patterns detected.