Back to skill

Security audit

腾讯云官网文档搜索 SKILL

Security checks for vulnerabilities and agentic risk

Overview

This skill is a disclosed Tencent Cloud documentation search helper and does not show hidden, destructive, or unrelated behavior.

Install only if you are comfortable using TCCLI and Tencent Cloud authentication on this machine. Prefer the documented OAuth login, avoid sharing SecretId or SecretKey unless you intentionally choose that path, and be aware that pip installation may update local Python packages.

Vulnerability Patterns
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (1)

Natural-Language Policy Violations

Low
Confidence
96% confidence
Finding
This markdown file contains user-facing instructions exclusively in Chinese, including the title, parameter descriptions, and usage guidance. Under the policy rule for language or locale constraints, forcing a single language without opt-in or justification is a natural-language policy concern.

Static analysis

No suspicious patterns detected.