Back to skill

Security audit

美业沙龙与大健康转化实战手册

Security checks for vulnerabilities and agentic risk

Overview

This is a disclosed marketing playbook, but it needs Review because it combines health-adjacent claims, recruitment conversion tactics, broad triggers, and inconsistent compliance guidance.

Install only if you intentionally want a Chinese beauty-salon marketing and direct-sales conversion assistant. Review generated content before publishing, especially health claims, product efficacy claims, before/after comparisons, recruitment language, and anything presented as legally compliant; the skill's compliance section is guidance, not a substitute for legal or platform-policy review.

Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
Findings (9)

Intent-Code Divergence

Medium
Confidence
90% confidence
Finding
The skill claims AI-generated copy will 'automatically execute' compliance checks and sensitive-word replacement, but the file only contains prose guidance and no enforceable implementation. This creates a false sense of safety, so operators may rely on nonexistent safeguards and publish noncompliant or risky marketing content.

Intent-Code Divergence

High
Confidence
97% confidence
Finding
The skill encourages 'before/after comparison' lead-generation content early in the document, but later says such content must not be generated due to compliance restrictions. This contradiction is dangerous because users may follow the earlier marketing instruction and produce regulated or deceptive advertising material despite the later disclaimer.

Vague Triggers

Medium
Confidence
86% confidence
Finding
The trigger list uses broad everyday terms that can activate the skill in unrelated conversations, increasing the chance that persuasive sales or health-marketing guidance appears when the user did not intend to invoke it. In this context, unintended activation is more concerning because the skill contains conversion, recruitment, and health-adjacent promotional playbooks.

Ssd 4

Medium
Confidence
89% confidence
Finding
The documented funnel explicitly guides users from trust-building into deeper product conversion and eventual business recruitment. While framed as business strategy, it operationalizes manipulative progression in a health-and-beauty context, which raises consumer protection and deceptive persuasion risks if surfaced without clear consent and guardrails.

Overly Broad Trigger

Low
Category
Trigger Abuse
Confidence
80% confidence
Finding
The trigger term '引流' is extremely short and generic, making accidental activation likely. Because the skill contains aggressive marketing and conversion guidance, unintended routing can expose users to inappropriate business playbooks in unrelated contexts.

Overly Broad Trigger

Low
Category
Trigger Abuse
Confidence
77% confidence
Finding
The trigger '康婷' is a short brand term that may appear in many benign discussions, causing unnecessary or unintended activation. In a skill centered on recruitment and product conversion, this increases the risk of unsolicited persuasive output.

Overly Broad Trigger

Low
Category
Trigger Abuse
Confidence
78% confidence
Finding
The trigger '抗糖' is broad and common in wellness conversations, so it can match unrelated user inputs. That is risky here because the skill may respond with sales or product-conversion workflows rather than neutral informational content.

Overly Broad Trigger

Low
Category
Trigger Abuse
Confidence
78% confidence
Finding
The term '抗衰' is widely used in ordinary beauty discussions and may trigger the skill unintentionally. Given the skill's combination of promotional content and compliance-sensitive claims, accidental activation can lead to problematic output generation.

Overly Broad Trigger

Low
Category
Trigger Abuse
Confidence
76% confidence
Finding
The trigger '茶道' is generic and likely to appear in unrelated cultural or lifestyle conversations. In this skill, such overbroad matching can unexpectedly route users into a sales-oriented conversion framework.

Static analysis

No suspicious patterns detected.