Back to skill

Security audit

产品分析大法-双轴洞察引擎

Security checks for vulnerabilities and agentic risk

Overview

This is a disclosed research-report skill that may use web research and save report files, with no hidden code, credential use, or destructive behavior found.

Install this if you want long, source-backed research reports. Before use, note that default PDF delivery may create files on your Desktop and in an analysis archive, and optional Feishu output may publish content into a third-party document system. Verify high-impact business, investment, policy, or technical claims independently.

Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Findings (1)

Missing User Warnings

Medium
Confidence
90% confidence
Finding
The skill defaults to generating a PDF at a local Desktop path (`~/Desktop/<报告名>.pdf`) without prominently warning that it will create files on the user's machine. Silent or implicit local file creation can surprise users, overwrite existing files if names collide, or expose sensitive report contents in a commonly synced or visible location such as the Desktop.

Static analysis

No suspicious patterns detected.