Back to skill

Security audit

Prompt Master - 提示词工程精华版

Security checks for vulnerabilities and agentic risk

Overview

This is a prompt-writing reference skill with disclosed optional auto-loading and no executable, data-access, or destructive behavior.

Review the optional auto-load setting before enabling it, because it can make these prompt-writing rules influence sessions by default. The skill otherwise appears to be a low-risk Chinese prompt template reference; users who prefer another language or precise rule numbering may want revisions before relying on it.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
Findings (3)

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The trigger conditions are broad and include optional auto-loading at session start, which can cause the skill to inject prompt-shaping instructions into conversations without a clear user request. In a prompt-management skill, unclear invocation boundaries increase the chance of unintended behavioral override, instruction collision, and persistent interference with other security-relevant system or task prompts.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
87% confidence
Finding

The markdown presents all instructions, triggers, and examples exclusively in Chinese, which can effectively impose a language preference on users without any opt-in or justification. Under the language/locale policy, this is a natural-language policy concern unless the skill explicitly offers language choice or states a valid region-specific constraint.

Content

No source excerpt is available for this finding.

Intent-Code Divergence

Low
Category
Not specified by scanner
Confidence
83% confidence
Finding

The document defines Rule 8 as a duplicate of '不知道就说不知道' at L114-L119, while later the rule-combination table maps 'AI回答太长' to rules 8 and 9 at L329 and the mnemonic maps rule 7 to '结论先行' and rules 8,9 to '简洁直接' at L342-L343. These internal references contradict the earlier rule definitions and could cause users to apply the wrong guidance.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.