Back to skill

Security audit

pan-xiaozi-search

Security checks for vulnerabilities and agentic risk

Overview

This skill is a disclosed web-search helper for a public cloud-drive index, but users should treat third-party file links as legal and security risks.

Install only if you want an agent to search pan.xiaozi.cc and show third-party cloud-drive share links. Verify legality before accessing results, avoid pirated media or cracked software, and do not enter credentials or download/run software from unfamiliar third-party pages.

Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (2)

Vague Triggers

Medium
Confidence
89% confidence
Finding
The trigger conditions are broad enough to activate on generic requests for cloud-drive links or shared resources, which can steer the agent into assisting with discovery of third-party file-sharing content without meaningful legality or safety gating. In this skill’s context, that is more dangerous because the indexed content explicitly includes movies, TV shows, software, and documents from public netdisk shares, increasing the chance of copyright-infringing or unsafe downloads.

Natural-Language Policy Violations

Medium
Confidence
95% confidence
Finding
The skill description and examples explicitly position the tool for finding shared movies, TV shows, software, and other cloud-drive resources, which materially facilitates access to potentially infringing or unauthorized content. This context increases risk because the service aggregates third-party sharing links at scale, making the skill a discovery layer for content that may violate copyright or expose users to malicious third-party download pages.

Static analysis

No suspicious patterns detected.