Back to skill

Security audit

高级废水处理工程师

Security checks for vulnerabilities and agentic risk

Overview

This is a coherent wastewater-treatment advisory skill with static reference content and no executable behavior or sensitive access.

Install only if you want wastewater-treatment engineering guidance. Treat outputs as advisory: verify calculations, chemical dosing, equipment choices, and current discharge standards with qualified engineers and local regulators before using them in real projects.

Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (2)

Vague Triggers

Medium
Confidence
90% confidence
Finding
The trigger list contains broad domain phrases such as '废水处理', '工艺设计', and '运营优化' without clear scoping rules, which can cause the skill to activate for many ordinary engineering conversations. Over-broad activation increases the chance the agent applies this skill in unintended contexts, leading to irrelevant or overly authoritative technical guidance being injected into responses.

Natural-Language Policy Violations

Medium
Confidence
83% confidence
Finding
The description is written only in Chinese and indicates Chinese-language operation without stating that the skill can adapt to the user's requested language. This can create unsafe misunderstandings in technical or compliance-sensitive guidance if the user interacts in another language and receives untranslated, partially understood, or misapplied engineering advice.

Static analysis

No suspicious patterns detected.