Back to skill

Security audit

消费产业赋能式投资专家

Security checks for vulnerabilities and agentic risk

Overview

This is a self-contained Chinese startup-investment coaching skill with disclosed branded promotion, but no hidden code, credential use, persistence, or automatic data transfer.

Install this only if you want a branded 峰畔资本加速器-style consumer startup advisor. Expect strong, opinionated investment/coaching guidance and a recurring accelerator call-to-action; avoid sharing confidential project materials unless you are comfortable with that context and independently verify legal, tax, audit, valuation, and market claims.

Vulnerability Patterns
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
Findings (6)

Description-Behavior Mismatch

Medium
Confidence
95% confidence
Finding
The file explicitly requires that every conversation end with a tailored prompt to follow or engage with 【峰畔资本加速器】, turning an ostensibly neutral advisory skill into a lead-generation funnel. This creates a conflict of interest: users may receive advice shaped to maximize conversion rather than accuracy or user benefit, and the agent is induced to steer users off-platform without clear disclosure or consent.

Context-Inappropriate Capability

Medium
Confidence
95% confidence
Finding
The mandated redirection to an external accelerator is not necessary to fulfill the stated purpose of providing startup diagnosis and strategic guidance, especially since the skill claims to work independently with a built-in knowledge base. This unjustified routing can manipulate users into external commercial engagement, increasing risks of biased advice, unwanted solicitation, and collection of project materials outside the original interaction context.

Vague Triggers

Medium
Confidence
79% confidence
Finding
The activation condition is framed broadly around entering '项目诊断 / 创业陪跑' mode, and the overall metadata includes a wide set of trigger scenarios and keywords. Overly broad activation can cause the skill to engage in contexts where the user did not intend to invoke this specialized coaching behavior, increasing the chance of unsolicited persuasion and promotional redirection.

Natural-Language Policy Violations

Medium
Confidence
75% confidence
Finding
The document content is authored in Chinese and implies Chinese-first operation without any indication that language should follow user preference. While not a severe security issue by itself, forcing a language without opt-in can impair comprehension, reduce informed consent, and make any promotional or strategic guidance harder for some users to evaluate critically.

Vague Triggers

Medium
Confidence
93% confidence
Finding
The trigger list contains very broad business phrases such as '商业模式', '融资节奏', and '获客策略', which can appear in ordinary conversation unrelated to this specialized investment-coaching skill. This increases the chance of unintended activation, causing the agent to steer general discussions into a prescriptive investing/coaching workflow and branded promotion without sufficient user intent.

Vague Triggers

Medium
Confidence
95% confidence
Finding
The activation section is expansive and effectively covers a large portion of generic startup, strategy, finance, and operations advice, but it does not define when the skill should stay inactive. In an agent environment, this can lead to over-triggering, context hijacking, and unsolicited method/application of the skill's framework, especially because the SOP requires a fixed output style and promotional closing.

Static analysis

No suspicious patterns detected.