Back to skill

Security audit

us-tech-giant-analyst

Security checks for vulnerabilities and agentic risk

Overview

This skill is a disclosed public-data research assistant for US tech-company analysis and does not request privileged access or hidden actions.

Install this only if you want a structured financial-analysis report generator that uses live public web data. Review outputs for freshness and source quality, and treat stock discussion as informational analysis rather than personal investment advice.

Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Findings (1)

Natural-Language Policy Violations

Medium
Confidence
94% confidence
Finding
The skill mandates Chinese section headings and a Chinese-first presentation structure regardless of the user's language, which can override user intent and create prompt-level steering that degrades reliability and user control. In a general analysis skill, forcing a specific output language/format without opt-in is risky because it can cause misalignment, reduce accessibility, and make the agent ignore explicit user preferences.

Static analysis

No suspicious patterns detected.