Back to skill

Security audit

Company Research Zh

Security checks for vulnerabilities and agentic risk

Overview

This is a Chinese-language company research report skill with no executable code, persistence, credential use, or hidden high-impact behavior found.

Installers should expect Chinese-language business research outputs and should verify any generated market, financial, or company facts against current reliable sources before using them for investment, vendor, or strategy decisions.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (2)

Natural-Language Policy Violations

Medium
Confidence
88% confidence
Finding
The skill is effectively written and exemplified only in Chinese, but it does not disclose that language constraint or give the user a choice of output language. This can cause silent routing into a skill the user may not understand, reducing transparency and increasing the chance of misunderstood outputs or missed warnings in a due-diligence context.

Vague Triggers

Medium
Confidence
91% confidence
Finding
The skill description contains broad trigger phrases for common business tasks like company research, due diligence, and competitor analysis without clear boundaries for when the skill should activate. This can cause overbroad or unintended invocation, leading the agent to steer ordinary user requests into this skill unexpectedly and potentially produce authoritative-seeming analysis without explicit user intent.

Static analysis

No suspicious patterns detected.