Back to skill

Security audit

杰哥黑客松交付

Security checks for vulnerabilities and agentic risk

Overview

This is a coherent Chinese-language MVP delivery skill that asks for confirmation before development and does not contain hidden execution, exfiltration, or persistence mechanisms.

Install this if you want a Chinese-language assistant workflow for turning internal project ideas into runnable MVPs. Review proposed project summaries before approving file creation, and be cautious with any requested deployment, production data access, or external service credentials.

Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Findings (1)

Natural-Language Policy Violations

Medium
Confidence
95% confidence
Finding
The display name, description, and default prompt are entirely in Chinese, which imposes a specific language on users. The file does not indicate that the skill is intended only for Chinese-speaking users or provide any opt-in or alternative locale, so this is a natural-language policy concern.

Static analysis

No suspicious patterns detected.