Back to skill

Security audit

RiskBlind Radar 风险盲区雷达

Security checks for vulnerabilities and agentic risk

Overview

This is a text-only decision-support skill that may ask proactive risk questions but does not request system access, credentials, network access, or hidden execution.

Install if you want an assistant that proactively challenges planning, spending, launch, commitment, and product assumptions. Expect occasional over-triggering from broad keywords, and keep the optional observation log disabled or periodically clear it if you do not want commitment or risk notes retained across conversations.

Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (8)

Vague Triggers

Medium
Confidence
89% confidence
Finding
The skill defines broad, loosely bounded activation logic such as triggering on 'specific topics' and asking a risk question before the end of each substantive conversation, but it does not specify clear topic boundaries, priority rules, or user-consent constraints. This can cause the skill to activate in many contexts where it is not appropriate, leading to intrusive behavior, prompt hijacking of unrelated conversations, and unreliable agent behavior that may override the user's actual intent.

Natural-Language Policy Violations

Medium
Confidence
81% confidence
Finding
The skill metadata and body are written entirely in Chinese and present the behavior as Chinese-first without stating language negotiation or fallback behavior. In multi-user or multilingual environments, this can cause unintended language forcing, confusion, or degraded usability, especially if the agent injects follow-up questions in a language the user did not choose.

Vague Triggers

Medium
Confidence
89% confidence
Finding
The trigger model is designed to fire automatically whenever broad topical language appears, and the stated principle is 'triggered then ask' rather than requiring stronger contextual confirmation. In a conversational skill, this can cause excessive or misaligned probing on ordinary user messages, creating prompt overreach, degraded UX, and potentially steering users into unintended decision framing.

Vague Triggers

Medium
Confidence
93% confidence
Finding
Many listed trigger phrases are extremely common in everyday speech, so the templates may activate during routine conversation rather than genuine risk-analysis moments. Because the skill is supposed to intervene proactively, these generic triggers increase the chance of false positives and conversation hijacking.

Vague Triggers

Medium
Confidence
95% confidence
Finding
The rule to scan every message for all trigger words and activate matching templates lacks sufficient constraints, which can lead to systematic over-invocation across nearly all interactions. In this skill's context, that means the agent may continuously inject questions, overwhelm the user, and distort the primary task through rigid keyword-driven behavior.

Vague Triggers

Medium
Confidence
93% confidence
Finding
The trigger phrases are very generic terms such as planning, spending, waiting, or commitment language, which are common in ordinary conversation. This can cause the skill to activate unexpectedly, steering conversations with unsolicited risk prompts and potentially disrupting user intent or biasing decisions even when risk analysis was not requested.

Vague Triggers

Medium
Confidence
89% confidence
Finding
The trigger table uses very broad phrases such as '投钱', '上线', and '计划做X', which are common in ordinary conversations and can cause the skill to activate far outside a narrowly intended risk-review context. This can lead to unsolicited steering of conversations, over-collection of decision context, and prompt-scope interference with other agent behaviors even if the content is not overtly malicious.

Vague Triggers

Medium
Confidence
85% confidence
Finding
The description is broad enough that the skill could activate in many decision-making or advisory conversations without clear boundaries. In an AI assistant context, overly broad activation can cause unintended interception of user workflows, unnecessary probing for sensitive context, or manipulation of decision processes beyond the user’s intent.

Static analysis

No suspicious patterns detected.