Back to skill

Security audit

Expert Insist

Security checks for vulnerabilities and agentic risk

Overview

This appears to be a behavior-guidance skill for advice and analysis, with broad activation and Chinese-only output as usability concerns rather than security abuse.

Install if you want a Chinese-language, opinionated advisory style. Be aware it may activate on broad phrases like requests for suggestions, analysis, or comparisons; use explicit instructions if you want another language or a neutral factual answer.

Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (3)

Vague Triggers

Medium
Confidence
92% confidence
Finding
The skill declares automatic activation for a very broad set of common opinion-seeking phrases, which can cause it to influence many routine conversations without explicit user opt-in. In a prompt-injection or instruction-priority context, broad auto-triggering increases the chance that this behavior overrides more task-appropriate handling, causes unnecessary hidden reasoning scaffolds to engage, or changes agent behavior in ways the user did not request.

Vague Triggers

Medium
Confidence
95% confidence
Finding
The auto-trigger conditions are very broad and match common advisory language such as '建议', '分析', and '哪个好', which can cause the skill to activate in many ordinary conversations without explicit user intent. Overly permissive activation increases the chance of unwanted behavioral override, where the assistant adopts a more opinionated and persistent stance in contexts that did not request this skill.

Natural-Language Policy Violations

Medium
Confidence
88% confidence
Finding
The skill is authored entirely as mandatory Chinese-language behavior with no language negotiation or user-preference check, which can cause it to apply instructions in a language the user did not request or understand. This is primarily a safety and usability control issue: it can degrade transparency, consent, and reliability, especially when the skill auto-activates broadly.

Static analysis

No suspicious patterns detected.