Back to skill

Security audit

赏金猎人

Security checks for vulnerabilities and agentic risk

Overview

This skill is mostly a disclosed freelancing and bug-bounty guide, but its security-testing section gives concrete scanning and exploitation-tool guidance without enough authorization scoping.

Review this skill carefully before installing if you do not want bug-bounty or offensive-security tooling suggestions. Use any scanning guidance only on systems you own, lab targets, or targets explicitly authorized and in scope for a bounty program; otherwise the freelancing and translation guidance is low-risk.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • YARA SignaturesMalware Match, Webshell Match, Cryptominer Match
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
Findings (4)

YARA rule 'offensive_tool_references': References to well-known offensive security tools [hacktools]

High
Category
YARA Match
Confidence
90% confidence
Finding

The skill includes explicit references to reconnaissance, scanning, and exploitation-adjacent security tools such as nmap, nikto, Burp Suite, sqlmap, and xsstrike in the context of earning money via bug bounty hunting. Although bug bounty can be legitimate, embedding operational tool guidance inside a general-purpose skill lowers the barrier to unauthorized scanning or misuse against non-consenting targets, making the content materially more dangerous in context.

Content

Scanner excerpt · references/details.md (reported line 182)May include surrounding context.

  • 专注子域名枚举
    • 找XSS/IDOR等中低危漏洞
    • 目标:$500-1000/月
  1. 进阶阶段(6-12月)

    • 审计API接口
    • 逻辑漏洞挖掘
    • 目标:$1000-5000/月
  2. 专业阶段(1年+)

    • 组合漏洞利用
    • 大厂赏金猎人
    • 目标:$5000+/月
text

**常用工具**:
```bash
# 子域名枚举
amass enum -passive -d example.com

# 端口扫描
nmap -sV -p 1-10000 target.com

# Web漏洞扫描
nikto -h https://target.com

# 被动收集
subfinder -d target.com | httpx

漏洞报告模板:

text
# [漏洞名称]

## 漏洞类型
[CWE-79: Cross-site Scripting]

## 严重程度
[Medium - 6.1]

## 漏洞描述
[详细描述漏洞及影响]

## 复现步骤
1. 访问 [URL]
2. 在 [参数] 输入 [Payload]
3. 观察 [结果]

## 修复建议
[提供修复方案]

## 影响范围
[影响的URL和用户数量]

补天(国内平台)

奖金范围:

漏洞类型奖金范围
信息�

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The trigger list includes very broad phrases such as '在线赚钱', 'freelance', '远程工作', and '任务平台', which can match many ordinary user requests that are not specifically asking for this skill. Over-broad activation can cause unintended routing, reduce user control, and surface monetization or bounty guidance in irrelevant contexts, increasing the chance of policy-bypassing or unsafe assistance being injected into normal conversations.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
98% confidence
Finding

Mandating Chinese-only output without considering the user’s language preference can cause mismatched responses, reduce usability, and create avoidable confusion in multilingual contexts. While not directly a security exploit, hard-coded language behavior can override user intent and interfere with safe, accurate communication, especially when platform names, legal terms, or security guidance may need precise localization.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

This markdown file is written entirely in Chinese and presents all guidance, templates, and operational instructions only in that language, with no indication that users may choose another language or locale. Under the stated policy, forcing a specific language without opt-in is a natural-language policy violation.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.