Back to skill

Security audit

Universal Business Skill System

Security checks for vulnerabilities and agentic risk

Overview

This is a broad business-automation skill that is not malicious, but it handles customer, user, event, CRM, and regulatory data without enough scoping or privacy controls.

Install only if you want a broad Chinese-language business workflow framework. Treat outputs as drafts, require explicit user confirmation before any CRM, database, public posting, regulatory, customer, or event-data action, and avoid feeding it personal or sensitive business data unless your organization has approved collection, retention, and access controls.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
Findings (18)

Vague Triggers

High
Category
Not specified by scanner
Confidence
97% confidence
Finding

The trigger list includes extremely generic business terms such as '业务', '运营', '内容', '数据', and '流程', which are likely to appear in many unrelated conversations. This creates a real risk of unintended invocation, causing the agent to load broad business workflows and instructions in contexts where the user did not explicitly request this skill.

Content

No source excerpt is available for this finding.

Vague Triggers

High
Category
Not specified by scanner
Confidence
97% confidence
Finding

The main body repeats a large, ambiguous trigger list without constraints, reinforcing auto-routing based on common business vocabulary rather than clear user intent. Because this is a universal business skill spanning 10 domains, accidental activation is especially risky: it could overtake many ordinary enterprise conversations and steer the agent into unnecessary file reads and workflow execution.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
83% confidence
Finding

The description and operating instructions are presented in Chinese throughout the file, but there is no statement that the skill is China-specific or that users may opt into another language. This can violate a language/locale policy if the organization requires language choice rather than forcing a single language by default.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

The social media and public-opinion monitoring unit instructs collection of platform data, sentiment, topics, and KOL/media mentions, but it provides no guardrails on privacy, lawful basis, retention, or compliance with platform terms. In practice, users could interpret this as authorization to scrape personal data or profile individuals across platforms, creating legal, privacy, and account-enforcement risk.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

This unit explicitly instructs collection of participant information, interaction data, and feedback data, but provides no requirement for notice, consent, lawful basis, minimization, or handling restrictions. In an event-operations skill, this omission can lead downstream agents or users to collect personal data in ways that violate privacy obligations or internal policy.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
89% confidence
Finding

The skill calls for end-to-end event data collection, cleaning, and reporting, including participation, interaction, conversion, and feedback data, without any warning about privacy, aggregation, or de-identification. Because this is framed as fully automatic, it increases the chance that personal or behavioral data will be processed and reported without adequate safeguards.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

This unit directs photo capture, screening, organization, and archival of event materials, and even includes a retention-related field, but does not require consent, signage, image-use authorization, or restrictions on storage and reuse. Photos from events can contain identifiable individuals, badges, minors, or sensitive context, making silent capture and long-term archival a meaningful privacy risk.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
88% confidence
Finding

The entire skill file is written as a Chinese-only specification and repeatedly defines outputs in Markdown without indicating that users may choose another language or locale. Per SQP-3, forcing a specific language without user opt-in can violate language/locale policy when no justified region-specific constraint is documented.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

The skill defines user behavior analysis, segmentation, funnel, and churn analysis workflows over user data without any accompanying privacy, consent, minimization, retention, or access-control guidance. In a reusable business skill system, this omission can lead downstream agents or operators to process personal or sensitive behavioral data in ways that violate privacy requirements or internal policy.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

The file title and all skill descriptions are written in Chinese, and every output field specifies Markdown deliverables in that same language context without any opt-in or alternative locale. Under the policy, a skill that effectively mandates a specific language should provide user choice or a documented justification for the locale constraint.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

This markdown skill specification uses Chinese throughout for headings, field labels, inputs, and outputs, effectively forcing a single language/locale for users and downstream operators. The file does not state that the skill is region-specific, nor does it offer an opt-in or alternative language, which matches the policy category for language or locale constraints without user choice.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The skill explicitly includes customer information collection, interaction logging, database maintenance, satisfaction assessment, and LTV analysis, but provides no privacy, consent, retention, access-control, or sensitive-data handling requirements. In a customer operations context, this omission can lead users to collect and persist personal or commercially sensitive data in ways that violate privacy law, internal policy, or least-privilege principles.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
88% confidence
Finding

The C8-25 unit defines CRM/业务系统数据录入维护 as semi-automated handling of business-system records, but the broader skill repeatedly promotes high-autonomy workflow execution and does not specify validation, authorization, audit, rollback, or segregation-of-duties controls for system updates. In a business automation skill, this can lead to incorrect, unauthorized, or bulk-corrupted operational records if the capability is implemented naively or over-trusted by downstream agents.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
86% confidence
Finding

The file defines several certification and regulatory workflows as fully automated, including approval tracking, renewal management, certificate ledgers, document management, and KPI handling, but provides no safeguards for sensitive business, regulatory, or potentially personal data processed in those flows. In a qualification/certification context, this can lead users to over-trust unattended handling of confidential submission identifiers, certificate records, timelines, and controlled documents without access controls, review gates, or privacy/compliance warnings.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The file title and core operating instruction are written entirely in Chinese, and it states that the file must be read on first use. There is no indication that other languages are supported or that the user can choose the interaction language, which can violate a language/locale policy requiring user choice.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
97% confidence
Finding

The entire skill file is written in Chinese and provides no indication that users may choose another language or locale. Under the policy, forcing a specific language without opt-in is a natural-language policy violation unless the locale restriction is explicitly justified, which is not present here.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
62% confidence
Finding

Natural-language policy issues can arise when a skill forces one language or locale without opt-in. This file is entirely presented in Chinese and does not state that language is configurable, optional, or justified as a region-specific skill.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
89% confidence
Finding

The entire skill reference is written in Chinese, beginning with the title at L001, and does not indicate that language selection is optional or limited to a specific region. This can violate language/locale policy when a skill implicitly mandates one language without user opt-in or justification.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.