Back to skill

Security audit

多账号启动器

Security checks for vulnerabilities and agentic risk

Overview

This skill transparently controls a local multi-account browser tool and writes a local result file, with no evidence of hidden external data transfer or destructive behavior.

Install this only if you intentionally use the referenced local multi-account matrix tool and are comfortable letting an agent list, start, or stop its browser accounts. Review account names before using fuzzy matching, and remember that operation results may be saved locally in last_result.txt.

Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Findings (1)

Natural-Language Policy Violations

Medium
Confidence
97% confidence
Finding
This code file includes natural-language documentation and CLI output entirely in Chinese, starting with the module docstring and continuing through usage/help text. Under the policy, forcing a specific language without offering a language or locale choice is a natural-language policy violation.

Static analysis

No suspicious patterns detected.