Back to skill

Security audit

PRD文档撰写助手Pro

Security checks for vulnerabilities and agentic risk

Overview

This is a Markdown-only PRD writing assistant whose behavior is limited to helping draft product requirement documents.

Install this if you want a Chinese-language PRD drafting template. Review generated PRDs for privacy, consent, and third-party data-flow details when the product being documented involves notifications, APIs, financial data, or user data.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Findings (3)

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The manifest description is written as a Chinese-only assistant description ('专业的产品需求文档(PRD)撰写助手') and the rest of the skill instructions are entirely in Chinese, with no indication that users may choose another language. Under the policy, forcing a specific language without user opt-in is a natural-language locale violation unless the constraint is explicitly justified.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

The PRD explicitly includes external notification via Feishu and external stock-market data retrieval, which implies transmission of user-configured alert data and use of third-party services. Although the document has a brief security section, it does not provide any user-facing disclosure, consent flow, or privacy requirements covering what data is sent externally, to whom, and under what retention/protection model.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
93% confidence
Finding

This markdown template uses Chinese throughout, including headings, labels, and instructional placeholders, which can impose a specific language on users without opt-in. Under the policy criteria, forcing a specific language without user choice is a natural-language policy concern unless the locale restriction is explicitly justified.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.