Back to skill

Security audit

像素级凝视

Security checks for vulnerabilities and agentic risk

Overview

This is a prompt-only visual inspection method that is disclosed, purpose-aligned, and does not add hidden tools, persistence, credentials, or file access.

Installers should expect this skill to make the agent spend more attention on image details, especially text, numbers, UI state, and screenshots. If you only want casual image descriptions, the broad trigger may be more active than necessary, but it does not introduce hidden system access or external data handling.

Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (1)

Vague Triggers

Medium
Confidence
89% confidence
Finding
The trigger scope is very broad: any request to analyze images, read text/numbers, or compare details may activate this skill. Overly broad activation can cause the agent to apply this methodology in many routine vision tasks without clear user intent or prioritization, creating prompt-routing conflicts and unexpected behavior; in agent self-review scenarios, it may also over-privilege image-based validation steps.

Static analysis

No suspicious patterns detected.