Back to skill

Security audit

Pitch Skill

Security checks for vulnerabilities and agentic risk

Overview

This skill is a text-only competitive pitch helper, but it encourages collecting insider-style stakeholder information without clear privacy or confidentiality guardrails.

Review before installing if your team handles confidential bids, regulated clients, or personal stakeholder data. Use it only with information you are authorized to share, avoid insider or improperly obtained details, and sanitize client materials before using external search or image-generation tools.

Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
Findings (4)

Vague Triggers

High
Confidence
95% confidence
Finding
The skill’s trigger definition is excessively broad and explicitly matches vague phrases like '帮我做个提案' or '客户要方案', which can cause the skill to activate in non-competitive or unrelated contexts. Because this skill drives a multi-agent strategic workflow aimed at winning pitches, unintended invocation can lead to inappropriate data collection, misleading strategic framing, and user confusion about the system’s role and scope.

Natural-Language Policy Violations

Medium
Confidence
88% confidence
Finding
The skill hard-codes Chinese as the default operating language and only conditionally switches output language based on upstream agent state, rather than explicitly honoring the user's language preference. In a multi-agent proposal workflow, this can cause user intent to be misinterpreted, reduce reviewability by non-Chinese-speaking stakeholders, and create prompt-steering behavior that overrides user control over outputs.

Missing User Warnings

Medium
Confidence
96% confidence
Finding
The skill explicitly asks the user for insider-style information such as internal contacts ('线人'), evaluator preferences, and private concerns without any warning to avoid confidential, improperly obtained, or personal data. In a competitive bidding context, this can facilitate unethical intelligence gathering, disclosure of non-public business information, and privacy violations, especially because the surrounding workflow is designed to exploit decision-maker fears and weaknesses for competitive advantage.

Natural-Language Policy Violations

Medium
Confidence
93% confidence
Finding
The file explicitly states that prompts 'must be in English' because image tools understand English better, which overrides likely user language preferences without opt-in or locale justification. In this Chinese-language skill, that can cause silent language switching, degraded usability, and unexpected transmission of user content into another language context, especially if proprietary pitch material is being reformulated for external AIGC tools.

Static analysis

No suspicious patterns detected.