Security audit
Biaoshu Writer Tech
Security checks for vulnerabilities and agentic risk
Overview
This skill is a disclosed client for a bid-document cloud API; it handles sensitive files and an App Key, but those behaviors fit its stated purpose and are clearly explained.
Before installing, be comfortable uploading tender and bid documents to the 招采猫 cloud service and using an App Key tied to account credits. Prefer manual credential setup if you do not want the App Key in chat history, and review generated files before submitting them externally.
Vulnerability Patterns
- Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
- Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
- Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
- Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
- Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Static analysis
No suspicious patterns detected.
