Back to skill

Security audit

work-critic

Security checks for vulnerabilities and agentic risk

Overview

This skill is a straightforward reviewer-style critique prompt with broad activation phrases but no code execution, data access, persistence, or hidden behavior.

Install this if you want direct, structured criticism of drafts, presentations, code plans, or application materials. Be aware that broad words like "critique" or "挑刺" may invoke the skill when you only meant a casual review request.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (4)

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The trigger phrases include very generic terms such as "请批评", "挑刺", "review", and similar reviewer-language that can appear in ordinary conversation unrelated to the skill. Overly broad activation increases the chance the skill is invoked unintentionally, causing unwanted critique behavior, possible context confusion, or disclosure of user content to the skill when the user did not explicitly intend to use it.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The trigger phrase "请批评" is broad and can appear in ordinary conversations where the user is not intentionally invoking this skill. This can cause unintended activation, making the agent switch into a harsh reviewer mode and potentially derail the intended task or reveal critiques the user did not ask for in that context.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

Several triggers, including phrases like "弱点在哪里", "review", and "reviewer", are ambiguous and common across unrelated workflows. Because the list mixes Chinese and English generic terms without contextual constraints, the skill may activate during normal editing, Q&A, or translation tasks, leading to prompt hijacking of the conversation flow.

Content

No source excerpt is available for this finding.

Overly Broad Trigger

Low
Category
Trigger Abuse
Confidence
94% confidence
Finding

The trigger "挑刺" is very short and colloquial, so it can easily match casual language that is not meant to invoke a formal skill. Short triggers increase accidental activation risk and make routing decisions less reliable, especially in multilingual or informal chat contexts.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.