Back to skill

Security audit

程序员客栈任务

Security checks for vulnerabilities and agentic risk

Overview

This is a text-only Chinese guide for using a freelancing platform; it raises privacy cautions but does not run code or collect data itself.

Install only if you want a manual guide for using Proginn. Do not share ID documents, account credentials, payment details, or private contact information with the agent; complete verification only through the official Proginn website or app. Prefer platform messaging, contracts, and payment protections before moving communication or payment off-platform.

Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Findings (1)

Missing User Warnings

Medium
Confidence
88% confidence
Finding
The skill explicitly instructs users to include external contact details such as WeChat and email in service descriptions, which can encourage sharing personal information outside the platform's protected workflow. In the context of a freelancing marketplace, this can bypass platform safeguards, increase privacy exposure, and create opportunities for fraud, off-platform solicitation, or social engineering.

Static analysis

No suspicious patterns detected.