Back to skill

Security audit

宠物行为训练方案台

Security checks for vulnerabilities and agentic risk

Overview

This is a Markdown-only pet behavior planning skill with no code execution, credential access, persistence, or external data transfer.

Reasonable to install if you want pet behavior plan drafting help. Treat outputs as general guidance, avoid sharing unnecessary personal details, and use a veterinarian or qualified behavior professional for aggression, self-harm, severe anxiety, medical symptoms, or safety-critical cases. The publisher should clarify which features are free versus Pro.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
Findings (4)

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
87% confidence
Finding

The trigger keywords include broad, common phrases such as '拆家' or '宠物训练' that can appear in ordinary conversation without clear intent to invoke this skill. Overly broad activation can cause the wrong skill to engage, leading to unintended processing of user-provided personal details or confusing workflow hijacking in multi-skill environments.

Content

No source excerpt is available for this finding.

Intent-Code Divergence

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

L20 明确写明“永久免费,无需付费、无需授权(MIT-0)”,给人的含义是该技能能力范围内不存在付费限制。但 L69 又写“批量处理、进阶段输出(异议应对/执行排期/记录表)与行业模板库属于增强能力,见同名 Pro 版本”,其中“记录表”还与前文 L26/L74 承诺的基础输出内容重叠,构成文档内部对能力边界与付费属性的直接冲突。

Content

No source excerpt is available for this finding.

Intent-Code Divergence

Medium
Category
Not specified by scanner
Confidence
97% confidence
Finding

L26 将“进度记录表”列为该技能的核心产出之一,L74 的示例输出也包含“记录表”,表明这是默认应提供的能力。但 L69 又称“进阶段输出(异议应对/执行排期/记录表)”属于增强能力并指向 Pro 版本,导致文档对同一输出是否属于基础免费能力产生直接矛盾。

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
90% confidence
Finding

The natural-language examples include generic follow-up instructions like '按上面的结果改成更简短的版本' and '把这些整理成一张表', which are not uniquely scoped to this skill. In a shared assistant environment, this ambiguity can cause accidental routing, context bleed, or unintended continuation of the skill when the user may be addressing another tool or asking for a general transformation.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.