Back to skill

Security audit

Product Dev Ops Package

Security checks for vulnerabilities and agentic risk

Overview

This is a Chinese-language product development workflow skill that creates and organizes project documentation in the workspace, with no evidence of hidden execution, credential access, exfiltration, or destructive system behavior.

Install only if you want a Chinese-language product development workflow. Before using /开工 or /归档, confirm the current workspace and project name because the skill can create folders, write project documents, append changelogs, and move work notes into an archive directory.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (40)

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

This markdown file presents the skill navigation, commands, and descriptions exclusively in Chinese, which can amount to a forced language choice if the skill is intended for general use. The file does not state that the skill is China-specific or offer an alternative language or opt-in for locale selection.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
81% confidence
Finding

The README instructs users to invoke the skill with Chinese-only slash commands such as '/开工', and the available commands section lists only Chinese command forms. There is no indication that users may choose another language or locale, which can violate language/locale policy when no opt-in is provided.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
86% confidence
Finding

This markdown file says the system will '自动' initialize a project directory, which implies file creation and modification. The README does not include any warning about where files will be created, what will be written, or that invoking the command changes the local filesystem.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
85% confidence
Finding

The skill description is presented as a Chinese-language operating model and the document consistently defines commands and behavior only in Chinese, without stating that users may choose another language. Under the policy, forcing a specific language or locale without opt-in is a natural-language policy concern.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The skill uses broad natural-language phrases like '我想做一个…' and '有个需求…' to trigger role switching automatically. This can cause unintended mode changes during ordinary conversation, making the agent follow a different persona or workflow than the user intended and increasing the chance of prompt-routing errors or unsafe action selection.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

The development-role trigger includes ambiguous text such as '帮我实现', '代码怎么写', and especially 'F00X' and '/继续 开发任务', which lacks precise activation boundaries. Ambiguous activation can route unrelated requests into implementation mode, causing the agent to bypass intended planning or review stages and produce code or operational guidance prematurely.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
84% confidence
Finding

The entire skill is written as a Chinese-only persona and interaction pattern, with no indication that users may choose another language or that the locale restriction is intentional and justified. This can violate language/locale policy when a skill implicitly enforces a specific language without user opt-in.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

The role activation keywords are broad natural-language phrases such as asking how to design an interface or choose a technical plan. In a multi-agent skill, this can cause unintended activation during ordinary discussion, allowing the architect persona to seize control or apply its constraints outside an explicitly requested handoff. The risk is higher because this role governs API contracts and can influence workflow decisions broadly.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
88% confidence
Finding

The skill content is written entirely in Chinese and presents its operating instructions and interaction model in that language without offering the user a language or locale choice. Under the policy, a fixed language requirement without opt-in or documented justification is a natural-language policy violation.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

The activation phrases include very broad, everyday requests such as asking how to write code or implement a feature, which can cause the skill to trigger outside its intended workflow. In a multi-skill or agentic environment, unintended activation can override user expectations, pull the model into this role unexpectedly, and lead to unauthorized development-oriented behavior or instruction precedence conflicts.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
88% confidence
Finding

The entire skill definition, examples, document responsibilities, and activation keywords are specified only in Chinese, with no indication that users may choose another language or that the skill is intentionally limited to a Chinese-speaking environment. Under the language/locale policy, a fixed language requirement without opt-in or justification is a natural-language policy concern.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

The activation keywords are broad, conversational phrases such as '谁来管这个系统?' and '成功的标准是什么?' that can easily occur during normal project discussion. This creates a scope/triggering weakness where the ops-manager skill may activate unintentionally, causing role confusion, unexpected instruction injection into unrelated contexts, or premature influence over the workflow.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
89% confidence
Finding

The skill directs the agent to write files like WHY.md and workshop outputs into workspace directories, but it does not require user confirmation or clearly warn that workspace content will be modified. In an agentic environment, this can lead to unexpected file creation or overwriting, which is especially risky when triggered implicitly through workflow stages.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The activation phrases are broad natural-language triggers such as '我想做一个…' and '有个需求…', which are common in ordinary conversation and can unintentionally switch the agent into a specialized role. This can cause unexpected behavior, including applying rigid workflow rules or generating project artifacts when the user did not explicitly request role activation.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
90% confidence
Finding

This is a markdown file, so SQP-2 applies to missing warnings in the skill description. Lines L054-L068 direct users to move documents into an archive path, which is a file-modifying operation, but the document provides no caution about file changes, backup considerations, or the impact on existing project organization.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
89% confidence
Finding

The trigger section lists general project-state conditions such as 'after the product workshop' and 'key decisions aligned' without defining hard criteria, exclusions, or negative examples. In a markdown skill file, this ambiguity can lead to premature or inconsistent invocation because users may interpret these milestones differently.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

This markdown file describes the command as resuming an interrupted process and includes a scenario of "任何流程卡住后恢复", which is very broad and lacks clear boundaries for when the skill should or should not be invoked. The file does not provide exclusion conditions or negative examples, increasing the risk of unintended invocation for many ordinary stalled workflows.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The command name, prompts, and workflow are entirely specified in Chinese, which imposes a language/locale constraint on users. The file does list an English alias at the end, but the interaction content itself does not offer language choice or opt-in, and no region-specific justification is provided.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

The command instructs the agent to automatically create a multi-level project directory tree in the current workspace without an explicit confirmation step immediately before the filesystem modification. In an agent environment, implicit writes can surprise users, affect the wrong workspace, or overwrite/contaminate existing project structure if the project name or current directory is not carefully validated.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

This markdown file defines the command trigger and usage only as '/状态', with no indication that users may invoke it in another language or choose their preferred locale. That creates a natural-language policy concern because the skill appears to require a specific language for activation without explicit opt-in or justification.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The file’s visible command name, section headings, and operational instructions are entirely in Chinese, and there is no indication that users may choose another language or that the skill is restricted to a China-specific or Chinese-only compliance context. This creates a natural-language policy concern because it effectively imposes a specific language without user opt-in.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

This OpenAPI template contains user-facing natural-language text in Chinese throughout, such as endpoint descriptions and environment labels. Because the template does not provide an opt-in, alternative locale, or justification for being region-specific, it may violate language/locale policy requirements.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

This markdown template is entirely written in Chinese, including headings and field labels, which imposes a specific language on users. The file does not indicate that the template is intended only for a Chinese-speaking team or provide any opt-in or alternative locale, which creates a language/locale policy concern.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

The markdown template is written almost entirely in Chinese placeholders and labels, which implicitly requires changelog authors to use a specific language. There is no note offering language choice or explaining that the template is intended only for a Chinese-language or region-specific workflow.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

This markdown template uses Chinese section headings and placeholder text throughout, which implicitly requires authors to work in Chinese. Under the policy, locale or language constraints should either be optional or explicitly justified; this file provides no opt-in or rationale.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.