Back to skill

Security audit

南山没有海·个人成长技能包

Security checks for vulnerabilities and agentic risk

Overview

This skill provides persona-style personal growth advice and does not request data access, commands, persistence, or account authority.

Install only if you want general coaching-style advice in this persona format. Do not treat it as professional medical, legal, financial, or crisis guidance; use qualified professionals for those topics.

Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (1)

Vague Triggers

Medium
Confidence
92% confidence
Finding
The skill advertises itself for 'any growth problem' and says to call the mentor group for any such issue, which creates an overly broad activation boundary. In an agent environment, this can cause the skill to be invoked for sensitive or inappropriate domains such as mental health, legal, financial, or other high-stakes advice without clear exclusions, increasing the chance of unsafe or low-authority guidance.

Static analysis

No suspicious patterns detected.