Back to skill

Security audit

"AI 产品经理教练。通过引导式对话帮助 PM 完成 AI 产品设计:从痛点分析到 PRD 输出。不替代 PM 决策,而是引导 PM 思考,在关键节点让 PM 做出选择。触发词:AI 产品、产品设计、PRD、能力边界、置信度、幻觉。" metadata:

Security checks for vulnerabilities and agentic risk

Overview

This Markdown-only AI product-management coach is purpose-aligned and does not request sensitive access, though its Chinese-only content and broad trigger terms should be understood before use.

Install this if you want a Chinese-language coaching workflow for AI PM and PRD design. Invoke it explicitly when possible, and be aware it may respond to broad terms like AI product, product design, or PRD.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
Findings (10)

Natural-Language Policy Violations

Medium
Confidence
81% confidence
Finding
The file title and all instructional content are written in Chinese, and the example dialogue and architectural descriptions consistently assume Chinese as the operating language. There is no indication that users may choose another language or that the Chinese-only scope is a justified locale-specific constraint.

Natural-Language Policy Violations

Medium
Confidence
94% confidence
Finding
The README presents the skill's core guidance, examples, and user-facing interaction style entirely in Chinese, including direct coaching language. This imposes a language/locale constraint on users without any opt-in, alternative language support, or explanation that the skill is intended only for a Chinese-speaking context.

Vague Triggers

Medium
Confidence
94% confidence
Finding
The trigger terms in the metadata are broad product-management phrases like 'AI 产品', '产品设计', and 'PRD', which can appear in normal discussion and may cause the skill to activate outside a user's explicit intent. In a subagent that can internally invoke other skills and steer the conversation, ambiguous activation increases the risk of unintended behavior, context capture, or workflow hijacking rather than direct code execution.

Natural-Language Policy Violations

Medium
Confidence
97% confidence
Finding
The natural-language content throughout the file assumes Chinese as the operating language, and there is no indication that users may choose another language or opt into this locale. Under the policy, forcing a specific language without user choice is a locale-policy concern unless the constraint is explicitly documented and justified.

Vague Triggers

Medium
Confidence
88% confidence
Finding
The startup example '我想设计一个 AI 产品' is a very generic sentence that a user could say during ordinary brainstorming, making accidental activation plausible. Because this skill is designed to take over the interaction flow and internally call other skills, such ambiguity can redirect a conversation without clear consent and expose surrounding context to unnecessary processing.

Natural-Language Policy Violations

Medium
Confidence
95% confidence
Finding
The skill content is entirely specified in Chinese, including the title, instructions, input labels, and output template, with no indication that language selection is optional or tied to a justified region-specific use case. This can violate language/locale policy because it implicitly constrains the skill to a specific language without offering the user or caller a choice.

Natural-Language Policy Violations

Medium
Confidence
90% confidence
Finding
The entire skill specification, including headings, inputs, outputs, and example trigger phrases, is written exclusively in Chinese and provides no indication that language is configurable or optional. Under the policy, a skill that implicitly enforces a specific language or locale without user opt-in can violate organizational language-choice requirements.

Natural-Language Policy Violations

Medium
Confidence
94% confidence
Finding
The entire skill description, inputs, and outputs are written only in Chinese, with no indication that language selection is user-configurable or that the skill is intentionally restricted to a Chinese-language environment. Under the policy, forcing a specific language without user opt-in or clear documented justification is a natural-language policy violation.

Natural-Language Policy Violations

Medium
Confidence
91% confidence
Finding
The entire skill specification is written only in Chinese, including the title, inputs, outputs, and evaluation instructions, with no indication that language selection is optional or region-specific. Under the policy, a skill that effectively requires a specific language without opt-in can constitute a locale/language policy violation.

Natural-Language Policy Violations

Low
Confidence
92% confidence
Finding
The entire skill instruction is written in Chinese and provides fixed Chinese confirmation phrasing, with no indication that language selection is optional or constrained by a justified locale-specific requirement. This can violate language/locale policy when a skill implicitly enforces one language without user opt-in.

Static analysis

No suspicious patterns detected.