Back to skill

Security audit

网络安全评估引擎专业版

Security checks for vulnerabilities and agentic risk

Overview

This skill is a disclosed cybersecurity assessment helper, but users should scope its scans and command use to systems they own or are authorized to assess.

Use this skill only for authorized defensive security reviews. Run its command examples from the intended repository or system scope, review Bash actions before execution, and avoid providing API keys or callback URLs unless they are necessary and trusted.

Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (2)

Vague Triggers

Medium
Confidence
92% confidence
Finding
The skill description advertises very broad security capabilities such as detection, compliance, vulnerability scanning, and encryption protection without tightly scoping what inputs, targets, or environments are authorized. In an agent-routing context, this can cause over-invocation on generic security-related prompts, increasing the chance the skill is selected for sensitive operations involving Bash, file access, or scanning behavior beyond the user's intent.

Vague Triggers

Medium
Confidence
89% confidence
Finding
The usage timing section says to use the skill whenever security detection, compliance audit, vulnerability scanning, or encryption protection is needed, which is still broad enough to match many common requests. Because the skill exposes Read/Write/Edit/Bash tools and includes command examples, loose invocation guidance raises the risk of the agent applying powerful operations in contexts where only advice or narrow analysis was intended.

Static analysis

No suspicious patterns detected.