Back to skill

Security audit

培训手册生成器

Security checks for vulnerabilities and agentic risk

Overview

This skill appears to be a coherent training-handbook document generator with no evidence of malware, exfiltration, destructive actions, or hidden privilege use.

Install if you want a Chinese-oriented professional training-handbook generator. Review the generated document formatting, especially fonts and locale assumptions, when creating English or multilingual materials.

Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (3)

Vague Triggers

Medium
Confidence
84% confidence
Finding
The trigger description is very broad and includes common generic document requests such as manuals, guides, and whitepapers, which can cause the skill to activate outside its narrowly intended use. Over-broad activation increases the chance that a user is routed into web research and document-generation behavior they did not request, potentially causing incorrect tool use, unnecessary data handling, or user confusion.

Vague Triggers

Medium
Confidence
80% confidence
Finding
The applicability section describes broad scenarios and ends with an open-ended catch-all for any document needing a cover, table of contents, pagination, and appendices. This ambiguity can lead to unintended activation for many ordinary report-writing tasks, increasing the risk of misrouting, over-collection of information, and inappropriate use of external research tools.

Natural-Language Policy Violations

Medium
Confidence
76% confidence
Finding
The skill hard-codes Chinese-language typography expectations, including Chinese fonts and East Asia XML font settings, without indicating that this is conditional on the user's language or locale. This can override user intent, produce inaccessible or unsuitable output for non-Chinese audiences, and cause formatting assumptions to propagate into generated documents without consent.

Static analysis

No suspicious patterns detected.