Back to skill

Security audit

A股复盘转公众号格式工具

Security checks for vulnerabilities and agentic risk

Overview

This is an instruction-only writing skill that formats user-provided text into WeChat article drafts and discloses local saving, with no evidence of hidden code or data transfer.

Install this only if you want a broad WeChat-article drafting helper. Review outputs before publishing, especially because it uses stock-review templates and may add finance-style structure. Avoid sending sensitive chats or private business notes unless you are comfortable with the generated draft being saved locally, and confirm or change the save location before use.

Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (3)

Vague Triggers

Medium
Confidence
91% confidence
Finding
The skill advertises applicability to '任意长文本' and very broad content classes without concrete trigger boundaries, making it likely to activate in contexts beyond the intended stock-review/article-formatting use case. Overbroad activation increases the chance the agent will process unrelated or sensitive user content and apply stock-publication behaviors, including downstream file writes, when the user did not explicitly request this skill.

Vague Triggers

Medium
Confidence
88% confidence
Finding
The activation scenarios describe generic needs like organizing drafts, meeting notes, reading notes, and industry analysis rather than specific invocation conditions. This ambiguity can cause unintended routing of common writing tasks into a skill that imposes a finance/WeChat-article structure and persistent storage behavior, potentially mishandling user data or producing misleading output in the wrong context.

Missing User Warnings

Medium
Confidence
95% confidence
Finding
The skill states that generated articles are automatically saved to disk under a default path without requiring an explicit opt-in or warning at execution time. Automatic persistence can expose sensitive user content, create unwanted artifacts, and overwrite or accumulate files in a privileged-looking directory, especially when users may expect only an in-chat transformation.

Static analysis

No suspicious patterns detected.