Back to skill

Security audit

大厂永生

Security checks for vulnerabilities and agentic risk

Overview

This is a prompt-only workplace communication analysis skill with no code, persistence, or hidden data access.

Before installing, be aware that the skill is designed for Chinese workplace communication analysis and may generate pointed workplace reply templates. Users should avoid sharing sensitive company secrets or personal data unless necessary, and should review any suggested messages before sending them at work.

Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (2)

Vague Triggers

Medium
Confidence
93% confidence
Finding
The trigger conditions are broad enough to activate on common phrases like '帮我看看这个', '分析一下这段对话', or generic mentions of cross-team issues, which can cause the skill to engage outside its intended niche. In a chat assistant setting, over-broad activation can misroute normal requests into a specialized framing that processes workplace conversation content unnecessarily and may produce manipulative or inappropriate advice in contexts the user did not intend.

Natural-Language Policy Violations

Medium
Confidence
85% confidence
Finding
The skill metadata and instructions assume Chinese-only behavior without offering language negotiation, which can lead to responses the user cannot understand or verify. In security terms this weakens informed user control and can cause miscommunication when the skill generates actionable workplace messaging in the wrong language.

Static analysis

No suspicious patterns detected.