Back to skill

Security audit

BigPlan · 产品调研(市场分析·技术评估·项目研发·产品方案)| Product Research & Planning

Security checks for vulnerabilities and agentic risk

Overview

This skill is a public product-research report template with no executable code, persistence, credential use, or hidden data handling.

Before installing, be aware that broad phrases like general requests to analyze a product may activate this skill. Its outputs are estimates based on public information, so treat BOM costs, pricing, timelines, and supplier assumptions as planning references that need independent validation.

Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (1)

Vague Triggers

Medium
Confidence
91% confidence
Finding
The trigger phrases are broad and include common-language terms such as '帮我分析', '产品方向', and '想做一款', which can cause the skill to activate during ordinary conversations that are not explicit requests for this capability. This increases the chance of unintended invocation, context hijacking, or the assistant steering a user into this skill when a more general response would be safer or more appropriate.

Static analysis

No suspicious patterns detected.