Back to skill

Security audit

测试右移

Security checks for vulnerabilities and agentic risk

Overview

This skill provides disclosed production-validation planning guidance and includes clear safety cautions, though users should treat its broad troubleshooting trigger carefully.

Install only if you want planning help for post-release validation, gray-release monitoring, rollback criteria, and chaos-engineering readiness. Do not let an agent use this skill to execute live production changes or experiments unless you have explicit authorization, a defined environment scope, privacy approval, and a tested rollback plan.

Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (1)

Vague Triggers

Medium
Confidence
85% confidence
Finding
The invocation example "上线后出了问题怎么办" is overly broad and can trigger the skill from a vague troubleshooting request without clear boundaries that the user specifically wants a production-validation or shift-right plan. In an agent setting, this can cause the model to activate production-focused guidance, including gray release, monitoring, and chaos engineering recommendations, in contexts where the user may only want incident advice, increasing the chance of unsafe or over-scoped operational actions.

Static analysis

No suspicious patterns detected.