Back to skill

Security audit

Workflow Dlc Pm Requirement

Security checks for vulnerabilities and agentic risk

Overview

The skill is a coherent PRD-writing workflow, but it needs review because it defaults to exporting PRD content to Feishu and persistently logs project details and document links.

Review before installing. Use this skill only in workspaces where Feishu export is acceptable, and ask the agent to confirm before creating external documents or writing local files. Avoid using it with confidential roadmap, partner, or customer data unless logging is disabled or sanitized.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (7)

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The trigger phrases include broad natural-language requests like '写 PRD' and '做需求', which are common workplace utterances and can cause the skill to activate when the user did not intend to launch a workflow with file writes and external document creation. In this skill, unintended activation is more dangerous because later phases direct persistent writes to local knowledge-base files, experience logs, and Feishu documents.

Content

No source excerpt is available for this finding.

Skill Enumeration

Medium
Category
Agent Snooping
Confidence
80% confidence
Finding

Skill enumerates or reads other installed skills. Access to other skills' SKILL.md files or the skills directory reveals prompt instructions, capabilities, and secrets that should be invisible to peer skills.

Content

Scanner excerpt · SKILL.md (reported line 29)May include surrounding context.

md
- 📐 **templates/prd-template.md** — PRD v2.0 模板(精简 7.N 五子章节 + R1-R6 规范 + 职责边界)
- 📋 **templates/project-versions.md** — 项目版本索引模板
- 💬 **skills/socratic-dialogue/SKILL.md** — 三步对话法(Phase 1 直接调用)
- 🧠 **knowledge-base/workflow-dlc/asset-inventory.md** — 可参考的 PRD 样例(某 B 端中台项目/某营销后台)

---

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The skill instructs writing project files such as knowledge-base/requirement/materials.md without clearly warning the user that persistent modifications will occur. This can lead to silent repository changes, accidental overwrites, or insertion of incomplete or sensitive business content into shared project files.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

The skill defaults to creating Feishu documents and returning links, but does not warn that project requirements content may be sent to an external system. Because PRDs often contain confidential roadmap, product, user-flow, and partner information, silent export to Feishu increases data leakage and access-control risk beyond the local environment.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
97% confidence
Finding

The skill writes structured experience logs containing project name, iteration details, PRD URL, goals, and workflow outcomes to a persistent raw file without informing the user. This creates a hidden audit trail of potentially sensitive business context and links, which may be retained longer than expected and exposed to other users or systems with file access.

Content

No source excerpt is available for this finding.

Ssd 3

Medium
Category
Not specified by scanner
Confidence
98% confidence
Finding

Persistent logging of conversation-derived project details into experience-base/raw/...-pm-req.json can capture sensitive user inputs in plain language, including business plans, goals, iteration status, and document links. In this skill context, the danger is elevated because PRD workflows routinely handle confidential pre-release information, making raw logs a valuable disclosure target.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
88% confidence
Finding

The description, prompts, and workflow instructions are all presented in Chinese and include quoted Chinese user utterances as the activation examples, which implies the skill expects Chinese-language use. There is no indication that users may choose another language or that the Chinese-only scope is a documented regional requirement.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.