Back to skill

Security audit

strategy-thinking

Security checks for vulnerabilities and agentic risk

Overview

This is a Chinese strategy-planning skill that gives structured advice and does not request hidden access, persistence, or unsafe authority.

Install this if you want a Chinese strategy-planning assistant. Expect opinionated planning structure and some Chinese-oriented documentation, but the inspected artifacts do not show hidden system access or automatic actions.

Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Findings (6)

Natural-Language Policy Violations

Medium
Confidence
95% confidence
Finding
The manifest description is written as an instruction entirely in Chinese, framing the skill's behavior for Chinese-language use. Combined with the file's later explicit language directive, this indicates a locale/language constraint without offering the user a choice or opt-in, which matches the policy category for forced language behavior.

Natural-Language Policy Violations

Medium
Confidence
99% confidence
Finding
The line '输出语言:直接、利索、有观点' appears within a Chinese-only skill specification and provides no option for the user to select another language or locale. A skill may recommend a style, but forcing a language/locale without opt-in is a natural-language policy violation under the stated rules.

Natural-Language Policy Violations

Medium
Confidence
92% confidence
Finding
This markdown file contains natural-language guidance and begins with a Chinese-only title, with the rest of the content also presented in Chinese. Under the language/locale policy rule, forcing a specific language without user opt-in or documented justification is a policy concern.

Natural-Language Policy Violations

Medium
Confidence
85% confidence
Finding
The skill content is entirely specified in Chinese and presents the method definition as normative runtime guidance, but it does not offer any user language choice or explain that the skill is intended only for a Chinese-language audience. Under the policy, forcing a specific language or locale without opt-in is a natural-language policy violation.

Natural-Language Policy Violations

Medium
Confidence
91% confidence
Finding
The file is written as normative runtime guidance in Chinese and gives mandatory behavior requirements for the skill, but nowhere offers the user a language or locale choice. Under the policy, forcing a specific language without user opt-in is a natural-language policy violation unless the locale constraint is explicitly documented and justified.

Natural-Language Policy Violations

Medium
Confidence
91% confidence
Finding
The title and document content are entirely in Chinese, and the file provides no indication that language choice is optional or limited to a justified region-specific context. Under the policy rule, forcing a specific language or locale without user opt-in is a natural-language policy violation.

Static analysis

No suspicious patterns detected.