Back to skill

Security audit

Official Document Skill

Security checks for vulnerabilities and agentic risk

Overview

This is a text-only Chinese official-document writing skill with no executable code, persistence, credential access, or hidden data handling.

Installers should understand that this skill is intended for Chinese official-document and government-style writing. Invoke it explicitly for that purpose, and avoid sending confidential or regulated government material unless it is appropriate for the agent environment you are using.

Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (1)

Vague Triggers

Medium
Confidence
91% confidence
Finding
The skill description is extremely broad and includes generic invocation phrases such as generate, revise, rewrite, humanize, and reduce AI flavor across many document types. In an agentic environment, this can cause over-triggering on ordinary writing requests, unintentionally routing unrelated or sensitive user content into this skill and expanding the skill's operational scope beyond what users expect.

Static analysis

No suspicious patterns detected.