Back to skill

Security audit

企业尽调报告

Security checks for vulnerabilities and agentic risk

Overview

This skill is a disclosed public-record enterprise due-diligence report generator, but users should be aware it can compile detailed company and related-person risk profiles.

Install only if you want full enterprise due-diligence reports. Before generating or sharing a report, confirm the target company, avoid unnecessary related-person profiling, check source terms and legal/privacy obligations, and treat the resulting HTML as a sensitive business document.

Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (3)

Vague Triggers

Medium
Confidence
88% confidence
Finding
The trigger phrases are broad enough to activate on generic requests such as '查询XX公司信息' or '帮我分析XX企业', which can cause the agent to launch a multi-source due-diligence workflow and compile a detailed HTML dossier without clear user intent for such extensive processing. In this skill’s context, that increases the chance of unnecessary collection, aggregation, and presentation of sensitive company and personal data from external sources.

Missing User Warnings

Medium
Confidence
93% confidence
Finding
The skill does not warn users that it will aggregate data from multiple external public-record sources and generate a structured HTML report containing potentially sensitive corporate and personal information, including legal-risk and related-person details. This lack of transparency can lead to unexpected large-scale profiling, overcollection, and accidental sharing of a more invasive artifact than the user anticipated.

Missing User Warnings

Medium
Confidence
94% confidence
Finding
The document explicitly instructs collection of extensive personal and sensitive enterprise-related risk data, including natural-person shareholders, actual controllers, managers, litigation, property clues, and consumption restriction records, but provides no privacy notice, lawful basis, minimization guidance, retention limits, or handling constraints. In a due-diligence reporting skill, this creates a real risk of over-collection, unlawful profiling, and misuse of sensitive personal information at scale, especially because multiple named data sources are aggregated into a structured report.

Static analysis

No suspicious patterns detected.