Back to skill

Security audit

龙虾直聘

Security checks for vulnerabilities and agentic risk

Overview

This skill is a disclosed recruiting and team-building helper that looks up company context and recommends skill packages, with installation gated on user confirmation.

Before installing, review the proposed skill package and approve only the skills you actually want added. Avoid entering confidential company details unless you are comfortable with them being used for lookup-based analysis, and treat fallback installs as a new confirmation decision.

Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (1)

Vague Triggers

Medium
Confidence
94% confidence
Finding
The skill enables implicit invocation but does not define a narrowly scoped trigger or clear user-consent boundary. In a skill that can search external sources and recommend or install role skill packs, this increases the chance the agent will activate automatically in loosely related conversations and steer toward unintended installations or external lookups without sufficiently explicit user intent.

Static analysis

No suspicious patterns detected.