Back to skill

Security audit

Competitor Intelligence Automation

Security checks for vulnerabilities and agentic risk

Overview

The skill is a coherent competitive-intelligence workflow that uses public web research and report generation without hidden persistence or unrelated access.

This skill is appropriate if you want Chinese-language competitor and market research reports. Before use, confirm the product names and scope, especially if your own product or roadmap is confidential, because the workflow is designed to run web searches using those names.

Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (1)

Vague Triggers

Medium
Confidence
95% confidence
Finding
The trigger conditions include very broad everyday phrases such as mentions of '竞品', '竞争分析', '对比', and '竞品研究', which can cause the skill to activate in contexts where the user did not explicitly intend to invoke it. Over-broad activation increases the chance of unintended web-driven competitive analysis, which can lead to irrelevant tool use, privacy issues if sensitive product names are included, and prompt-scope confusion in larger agent workflows.

Static analysis

No suspicious patterns detected.