Back to skill

Security audit

全能文案助手

Security checks for vulnerabilities and agentic risk

Overview

This is a plain copywriting instruction skill with no executable code, persistence, credential access, or hidden system behavior.

Reasonable to install if you want a general Chinese copywriting helper. Review outputs carefully for regulated topics such as medical, financial, or legal marketing, and do not rely on it as compliance review or professional advice.

Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (1)

Vague Triggers

Medium
Confidence
85% confidence
Finding
The skill is broadly positioned as a general-purpose copywriting assistant without clear activation boundaries, prohibited use cases, or refusal conditions for risky requests. In practice, that can cause the agent to over-apply the skill to sensitive domains such as medical, financial, legal, or deceptive marketing content, increasing the chance of unsafe or noncompliant outputs.

Static analysis

No suspicious patterns detected.