Back to skill

Security audit

知识IP工坊

Security checks across malware telemetry and agentic risk

Overview

This skill is a disclosed Chinese-language planning assistant for turning professional expertise into content, courses, and monetization plans.

Before installing, note that the skill is primarily written for Chinese-language knowledge-IP and course-planning workflows and may use web search when analyzing competitors. Its revenue estimates are advisory and should not be treated as guaranteed financial outcomes.

Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (2)

Vague Triggers

Medium
Confidence
87% confidence
Finding
The trigger conditions include a broad catch-all phrase covering general topics like knowledge-system building, course design, IP positioning, and content planning. This can cause the skill to activate outside the user's explicit intent, potentially hijacking unrelated conversations and steering responses into this workflow when the user wanted a different tool or neutral assistance.

Natural-Language Policy Violations

Medium
Confidence
80% confidence
Finding
The metadata and examples are written entirely in Chinese and imply Chinese-language interaction by default, without stating that the assistant should adapt to the user's language. This can degrade usability, exclude users, and lead to incorrect or inaccessible responses when the surrounding conversation is in another language.

VirusTotal

64/64 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.