Back to skill

Security audit

Popeye Business

Security checks for vulnerabilities and agentic risk

Overview

This is a Chinese-language business writing helper made of Markdown templates, with no code execution, persistence, credential access, or hidden data handling.

Install this if you want Chinese-language templates for business plans, marketing plans, and competitor analysis. Be aware that generic prompts like asking for a marketing plan may route into this skill, and business details you provide will be used in the generated output, but the artifact itself does not run code or access external data.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (7)

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
84% confidence
Finding

The manifest description lists trigger words inline, but one of them is phrased broadly enough that it could be used in ordinary discussion of business topics rather than as an explicit skill invocation. The file does not provide exclusion conditions or activation boundaries to clarify when these phrases should or should not trigger the skill.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The entire skill, including the title, trigger phrases, prompt template, and example dialogue, is written exclusively in Chinese and implies operation in that language only. There is no indication that users may choose another language or that the Chinese-only constraint is a documented, region-specific requirement.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
87% confidence
Finding

全文标题、触发词、提示模板和示例均固定为中文,未说明用户可选择其他语言或按用户输入语言响应。根据 SQP-3,若技能强制特定语言且没有用户选择或明确合理的区域性约束,属于语言/locale 策略问题。

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The trigger phrase includes a very common natural-language expression ('帮我分析竞品'), which increases the chance that the skill activates unintentionally during ordinary conversation. In an agent setting, accidental activation can cause the model to switch into this skill's prompt template unexpectedly, leading to misrouting, irrelevant outputs, or disclosure of user business context to the wrong workflow.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
88% confidence
Finding

The skill content is entirely hardcoded in Chinese and implicitly requires Chinese output without checking the user's language preference or documenting a locale restriction. This can cause misrouting, user confusion, and policy/application-layer errors in multilingual environments, though it is not directly a code-execution or data-exfiltration issue.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The trigger phrases are generic business/assistant requests rather than narrowly scoped commands, so the skill can activate on ordinary user prompts that merely ask for a marketing plan. That increases unintended routing and prompt hijack surface, because users may be forced into this rigid template when they did not explicitly opt into the skill.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
93% confidence
Finding

The manifest description and user-facing instructions are entirely in Chinese, which effectively forces a specific language for interaction. There is no opt-in, alternative language option, or justification that this skill is intended only for a Chinese-language audience.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.