Back to skill

Security audit

ALIWAY

Security checks for vulnerabilities and agentic risk

Overview

This is a writing-style guide that only steers document tone and structure, with no code, data access, persistence, or hidden behavior found.

Install it if you want Chinese Alibaba-style strategic writing assistance. Be aware it may make outputs more forceful or management-oriented when prompts contain broad strategy terms, so explicitly ask for a neutral style when that is not desired.

Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (1)

Vague Triggers

Medium
Confidence
93% confidence
Finding
The skill advertises activation on broad, generic phrases such as 'CTO视角', '使命愿景', '顶层设计', and ordinary requests to write in an '阿里风格'. Those cues can appear in many normal documentation tasks, causing the skill to trigger outside its intended niche and unexpectedly steer outputs toward a forceful strategic-management style. In this context, the issue is not code execution but scope overreach and prompt hijacking of unrelated writing tasks.

Static analysis

No suspicious patterns detected.