Back to skill

Security audit

询问笔录

Security checks for vulnerabilities and agentic risk

Overview

This is a disclosed document-generation skill for inquiry transcript workflows, with safeguards against inventing facts and no executable install behavior found.

Before installing, consider that the skill is meant to process sensitive inquiry and transcript materials. Use it only with documents you are allowed to share with your agent environment, keep sensitive records away from unrelated external services, and manually verify every generated transcript before use.

Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep

Static analysis

No suspicious patterns detected.