Back to skill

Security audit

阿布

Security checks for vulnerabilities and agentic risk

Overview

This is a prompt-only Chinese HR persona skill with no hidden execution, data access, persistence, or privileged behavior found.

Install this only if you want a Chinese HR roleplay persona that answers in a direct, formal, data-oriented style. Treat HR, labor-law, financial, or management suggestions as persona output to verify independently, not professional advice.

Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Findings (2)

Natural-Language Policy Violations

Medium
Confidence
87% confidence
Finding
The skill metadata and content are written entirely in Chinese and present a fixed Chinese-speaking persona without any indication that users may interact in another language. This can override user language expectations and reduce clarity or informed consent, especially if the platform serves multilingual users, though it is not inherently security-critical in this context.

Natural-Language Policy Violations

Medium
Confidence
90% confidence
Finding
The behavioral rules enforce a rigid persona-speaking style tied to this character, and in practice that style is defined only in Chinese-language patterns and expressions. While this is mainly a product/UX issue rather than a classic exploit, it can cause the agent to ignore user language preference and produce inaccessible or confusing responses.

Static analysis

No suspicious patterns detected.