Back to skill

Security audit

Hainan Cost Index

Security checks for vulnerabilities and agentic risk

Overview

This is a domain-specific Hainan construction cost reference skill with only minor routing-scope concerns, not evidence of harmful behavior.

Reasonable to install for Hainan construction cost reference work. Users should treat estimates as advisory, verify important figures with official/current sources or a professional consultant, and consider narrowing activation triggers so generic estimation requests do not invoke this skill unexpectedly.

Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (3)

Vague Triggers

Medium
Confidence
90% confidence
Finding
The description includes broad trigger phrases like ‘投资估算’, ‘造价对比’, and ‘经济指标’, which are generic enough to match many unrelated conversations. Overly broad activation can cause unintended invocation of the skill, leading to context hijacking, irrelevant outputs, or interference with other more appropriate skills.

Vague Triggers

Medium
Confidence
93% confidence
Finding
The main trigger word list contains multiple ambiguous activation conditions, including generic terms for estimation, comparison, and pricing that are not uniquely tied to this skill. In a multi-skill environment, this increases the chance of accidental routing and may expose users to incorrect domain assumptions or unnecessary file-backed processing.

Vague Triggers

Medium
Confidence
91% confidence
Finding
The trigger list includes generic phrases such as "投资估算" and "造价对比", which can match many ordinary construction-cost queries outside a narrowly defined Hainan-specific scope. This can cause the skill to activate in unintended contexts, leading to misrouting, irrelevant responses, or overcollection of user context, even though the manifest does not show overtly malicious behavior.

Static analysis

No suspicious patterns detected.