Back to skill

Security audit

How To Creat Opc

Security checks for vulnerabilities and agentic risk

Overview

This is a Chinese-language startup guidance skill with no executable code, hidden behavior, or privileged access requests.

Install this if you want Chinese guidance on AI-native startup workflows. Expect broad business-strategy advice and references to Claude products, but the artifact itself does not run code or access your data.

Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (2)

Vague Triggers

Medium
Confidence
85% confidence
Finding
The skill metadata describes very broad activation conditions such as entrepreneurship guidance, AI startup methodology, and one-person company operations. This can cause the skill to be invoked in many generic business-advice contexts where a narrower or more specialized skill would be more appropriate, increasing the chance of unintended routing and irrelevant guidance.

Natural-Language Policy Violations

Medium
Confidence
80% confidence
Finding
The skill description is written as Chinese-only and implies a fixed language behavior, which can conflict with higher-level locale or user-language policies. If invoked for users in other languages, it may produce responses in the wrong language or bypass expected localization behavior, degrading usability and policy compliance.

Static analysis

No suspicious patterns detected.