Back to skill

Security audit

Agent Evaluation Report

Security checks for vulnerabilities and agentic risk

Overview

The skill appears intended to generate agent test reports, but it can write those reports to a preset Feishu location or local files with broad triggers and no clear confirmation step.

Review before installing. Use it only when you intentionally want an AI or intelligent-agent evaluation report, confirm the exact Feishu document destination or local path before any write, and avoid supplying confidential test data unless the Feishu workspace and app permissions are appropriate.

Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (3)

Vague Triggers

Medium
Confidence
88% confidence
Finding
The skill advertises broad trigger phrases like '创建测试报告' and '项目测试报告' without narrowing them to this specific report type, which can cause unintended invocation for generic reporting requests. Because the skill has write-capable tools and a predefined Feishu destination, accidental activation could lead to unexpected document creation or modification.

Vague Triggers

Medium
Confidence
91% confidence
Finding
The documented trigger conditions list several common phrases but provide no scope boundaries, disambiguation rules, or negative examples, making it easy for unrelated requests to match. In this context, ambiguity is more dangerous because the skill is designed to generate formal artifacts and can write them to external storage locations.

Missing User Warnings

Medium
Confidence
95% confidence
Finding
The skill metadata and body indicate write access to Feishu documents and local files, but the user-facing description does not clearly warn that provided data may be persisted externally. This creates a data handling and consent risk, especially if users supply sensitive test results, defect details, or internal project information expecting only transient processing.

Static analysis

No suspicious patterns detected.