Back to skill

Security audit

Product Dev Workflow V5

Security checks for vulnerabilities and agentic risk

Overview

This skill is a Chinese product-development report template and does not request sensitive access, tools, persistence, or data handling.

Install this if you want a Chinese, one-shot product development report workflow. Be aware it may activate on broad product-planning phrases and may not ask clarifying questions before generating a long report.

Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (2)

Vague Triggers

Medium
Confidence
95% confidence
Finding
The trigger conditions are extremely broad (e.g. '帮我做产品方案', '开发一款XXX') and the skill text says it must be used whenever such phrases appear. This can cause the agent to invoke this workflow for many generic product-planning requests where a narrower or user-selected tool would be more appropriate, reducing user control and increasing the chance of unintended behavior.

Natural-Language Policy Violations

Medium
Confidence
87% confidence
Finding
The skill requires all output to be in Chinese without checking the user's language preference or explaining an operational necessity. While not directly a security exploit, this can degrade safe and accurate interaction by preventing the agent from honoring user intent and can cause misuse in multilingual contexts.

Static analysis

No suspicious patterns detected.