Back to skill

Security audit

撒打算

Security checks for vulnerabilities and agentic risk

Overview

This is a vague placeholder skill with no executable behavior or sensitive access, so it appears low-risk but not useful.

Before installing, understand that this skill does not meaningfully describe what it does or when it should run. It appears safe from a security perspective, but it should be treated as an unfinished placeholder unless the publisher clarifies its purpose and operating boundaries.

Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (1)

Vague Triggers

Medium
Confidence
95% confidence
Finding
The skill manifest and description are so vague that they do not define what the skill is supposed to do, when it should activate, or what boundaries it should follow. This ambiguity can cause unintended invocation, misrouting, or unsafe behavior because downstream systems and users cannot reliably determine the skill’s permitted scope or expected actions.

Static analysis

No suspicious patterns detected.