Back to skill

Security audit

头脑超级风暴

Security checks for vulnerabilities and agentic risk

Overview

This is a plain markdown brainstorming workflow that is coherent with its stated purpose, though users should review its file-writing and git-commit steps before use.

Install this only if you want a structured brainstorming step before design or feature work. Ask the agent to use your preferred language, keep project inspection scoped, and require explicit approval before it writes files or creates git commits.

Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Findings (1)

Natural-Language Policy Violations

Medium
Confidence
94% confidence
Finding
The skill content is entirely written in Chinese and implicitly directs the agent to operate in Chinese without checking the user's language preference. This can degrade usability, cause misunderstandings, and create consent/policy issues when users expect interaction in another language, especially in planning and implementation workflows where precision matters.

Static analysis

No suspicious patterns detected.