Back to skill

Security audit

Eric's Engineering Wisdom

Security checks for vulnerabilities and agentic risk

Overview

This is a Chinese engineering-advice routing skill with broad activation and persona framing, but no evidence of code execution, credential access, exfiltration, destructive behavior, or hidden installation behavior.

Install only if you want a Chinese, Eric-branded engineering advisor that may proactively route broad engineering questions and include personal-experience-style judgment. Treat the advice as technical guidance to verify against your own constraints, especially for safety-critical engineering decisions.

Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (35)

Vague Triggers

Medium
Confidence
87% confidence
Finding
The skill description activates on broad concepts like engineering problems, product development, technical diagnosis, fault analysis, and even ambiguous descriptions. This can overlap with many ordinary conversations and cause unintended routing, which may lead the agent to apply specialized instructions or persona framing when the user did not request it.

Vague Triggers

Medium
Confidence
90% confidence
Finding
Positioning the skill as the 'first-entry router' for general engineering issues without precise boundaries makes it prone to over-triggering. In practice, this can hijack adjacent topics, pull in unnecessary sub-skills, and steer the conversation under a fixed workflow even when a lighter or different response would be safer and more appropriate.

Natural-Language Policy Violations

Medium
Confidence
83% confidence
Finding
The skill metadata and content are written to present the skill in Chinese and do not indicate that the user's language preference should control the response. This can override user expectations, reduce comprehension, and create consent and usability issues, especially in mixed-language or non-Chinese contexts.

Vague Triggers

Medium
Confidence
92% confidence
Finding
The skill is positioned as a 'first entry' router for broad engineering questions and explicitly triggers on vague technical problem descriptions. In an agent system, this can cause over-activation on common requests, leading to inappropriate interception, unnecessary context loading, and a higher chance of the skill steering answers outside the user's intended scope.

Natural-Language Policy Violations

Medium
Confidence
88% confidence
Finding
The instruction that responses should 'always' include a personal 'Eric's engineering judgment' section imposes a fixed persona and source-framing regardless of user request. This can misrepresent provenance, create undue authority bias, and pressure the agent to present anecdotal or personalized judgment as required content even when unsupported or unwanted.

Vague Triggers

Medium
Confidence
86% confidence
Finding
The trigger keywords are very broad engineering nouns such as 电机, 振动, 噪声, and 齿轮, without clear scope guards or disambiguation rules. In a routing skill that acts as a first-entry controller, this can cause unintended skill activation, over-broad context loading, and misrouting of user requests, which may produce incorrect technical guidance or expose unrelated sub-skill behavior.

Natural-Language Policy Violations

Low
Confidence
88% confidence
Finding
The file is entirely written in Chinese and presents the skill as a general entry point for engineering questions, but it does not offer a user language choice or document that the skill is intentionally limited to Chinese-speaking users. This can cause user exclusion, misunderstanding of technical guidance, and unsafe downstream use if non-Chinese-speaking users rely on partially understood engineering advice.

Vague Triggers

Medium
Confidence
88% confidence
Finding
The file describes this skill as the 'first entry point' for broad engineering questions and explicitly says it should trigger when problem descriptions are vague or uncertain. That broad routing scope can cause over-triggering, pulling this skill into conversations outside its intended domain and increasing the chance of inappropriate guidance, unnecessary context loading, or misclassification of user intent.

Vague Triggers

Medium
Confidence
89% confidence
Finding
The file states that this judgment layer is 'automatically loaded' whenever related domains are involved, but it does not define narrow activation boundaries. In a routing skill that serves as a first entry point for broad engineering questions, this can cause unintended context injection, overreach into unrelated requests, and hidden instruction influence on downstream responses.

Natural-Language Policy Violations

Medium
Confidence
83% confidence
Finding
The content is written as a directive to embed a personal engineering judgment layer and appears to prescribe Chinese-language behavior without confirming the user's preference. Forced language behavior can override user intent, reduce usability, and create a prompt-injection style policy conflict when the surrounding system expects language selection to follow the user's request.

Vague Triggers

Medium
Confidence
92% confidence
Finding
The skill’s trigger scope is very broad: it claims to be the 'first entry point' for engineering questions and to activate on vague descriptions, product development, technical diagnosis, and fault analysis. This can cause over-triggering and context hijacking, where the skill activates for many loosely related conversations and steers responses into its own routing framework even when a more appropriate skill or default behavior should apply.

Natural-Language Policy Violations

Medium
Confidence
88% confidence
Finding
The skill description and output expectations are written to default into Chinese phrasing without offering language negotiation or preserving the user’s language. This can override user intent, reduce usability, and in multi-skill settings may create prompt-level conflicts where the skill imposes a response language unrelated to the user’s request.

Vague Triggers

Medium
Confidence
84% confidence
Finding
The trigger description is very broad and targets generic engineering questions as a 'first entry point,' which can cause the skill to activate for loosely related or ambiguous conversations. Over-broad routing increases the chance of misclassification, unnecessary context loading, and instruction interference from unrelated subskills, which can degrade safety and reliability.

Natural-Language Policy Violations

Medium
Confidence
78% confidence
Finding
The description and behavior are written to operate in Chinese without stating that the assistant should adapt to the user's language. This can cause mismatched responses, misunderstanding of safety-critical engineering advice, and reduced usability for users communicating in another language.

Vague Triggers

Medium
Confidence
88% confidence
Finding
The skill declares itself as the 'first entry routing' for broad categories like engineering problems, product development, technical diagnosis, and even vague problem descriptions. This can cause overbroad activation on common user requests, leading the agent to invoke this skill when a narrower or more appropriate skill should respond, which increases the chance of irrelevant guidance, unintended routing, or context hijacking across domains.

Natural-Language Policy Violations

Medium
Confidence
80% confidence
Finding
The skill content is written entirely in Chinese and structures output around Chinese-language responses without offering user language choice. This can create instruction-priority conflicts and reduce reliability for users operating in other languages, potentially causing misunderstanding of technical or safety-critical engineering advice.

Vague Triggers

Medium
Confidence
87% confidence
Finding
The trigger list includes very broad terms such as 工程问题, 产品开发, 技术诊断, and 故障分析 at the skill level, which can cause the router to activate this skill for loosely related requests outside its intended engineering hardware scope. In a first-entry routing skill, overbroad activation increases the chance of misrouting, unnecessary loading of subordinate skills, and unsafe or low-quality domain advice being presented with undue authority.

Natural-Language Policy Violations

Medium
Confidence
86% confidence
Finding
The file explicitly frames the content as a personal engineering judgment layer embedded into the skill and the static finding indicates it forces Chinese output without user choice. Hard-coding a response language can override user intent, reduce accessibility, and create prompt-routing behavior that is inconsistent with the user’s requested language, which is a real quality and safety issue for an agent skill even if it is not a classic security exploit.

Vague Triggers

Medium
Confidence
88% confidence
Finding
The trigger keywords are very broad domain terms such as 电机, 齿轮, 振动, and 噪声, which are likely to appear in many legitimate engineering conversations. In a top-level routing skill, this can cause unintended invocation or over-broad loading of subordinate skills, increasing the chance of misrouting, unnecessary context exposure, and incorrect expert guidance.

Vague Triggers

Medium
Confidence
89% confidence
Finding
The skill description activates on very broad concepts such as engineering problems, product development, technical diagnosis, failure analysis, and even vague descriptions. That can cause the skill to intercept many general requests outside its intended scope, increasing the chance of misrouting, irrelevant persona injection, or unrequested use of downstream skills. In a routing skill, overbroad activation is especially risky because it becomes a gateway for additional instructions and policy shaping.

Vague Triggers

Medium
Confidence
92% confidence
Finding
The workflow explicitly treats ambiguous user input as a trigger for this skill and instructs broad domain matching across multiple areas. That makes the router prone to over-capture and speculative classification, which can lead to incorrect delegation, unnecessary expansion into unrelated domains, and reduced user control over how the request is handled. Because this skill is a first-entry router, boundary mistakes can propagate into all child skills.

Natural-Language Policy Violations

Low
Confidence
76% confidence
Finding
The instruction to always include Eric's personal judgment section forces a specific framing and authority signal even when the user did not request it. This is a style and trustworthiness concern because it can overstate personal expertise, bias the response, and reduce transparency about what is general knowledge versus anecdotal experience. In a technical advisory skill, mandatory persona-driven guidance can nudge users toward unsupported conclusions.

Vague Triggers

Medium
Confidence
91% confidence
Finding
The skill is designed as a broad first-entry router for engineering questions, with trigger conditions like '工程问题、产品开发、技术诊断、故障分析' and even ambiguous cases. That makes activation overly permissive and increases the chance it intercepts general requests outside its intended scope, steering responses through this skill’s framing and child-skill routing when a narrower or more appropriate skill should handle them.

Natural-Language Policy Violations

Low
Confidence
78% confidence
Finding
The description requires answers to be fused with 'Eric的个人经验与工程判断,' forcing a named personal perspective without offering the user a neutral style option. While not directly enabling code execution or data exfiltration, this can bias outputs, reduce transparency, and make the assistant present subjective judgment as authoritative engineering advice.

Vague Triggers

Medium
Confidence
84% confidence
Finding
The trigger keywords are very broad generic engineering terms such as 电机, 振动, 噪声, and 齿轮, so the orchestrator may activate this skill or related sub-skills for ambiguous user requests that only loosely match the intended scope. In a routing skill, overbroad activation can expose unrelated instructions, cause unintended cross-skill loading, and increase the attack surface for prompt-injection or misrouting from untrusted user input.

Static analysis

No suspicious patterns detected.