Back to skill

Security audit

AI大模型专家|GEO AEO 内容增长中心

Security checks for vulnerabilities and agentic risk

Overview

This skill is a disclosed content-planning assistant that emphasizes source-backed claims and does not include hidden code, persistence, or destructive behavior.

Before installing, use this skill with approved brand or product materials and review generated claims, images, and videos before publishing. Be especially careful with regulated topics, competitor comparisons, pricing, partnership claims, and anything presented as evidence-backed.

Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (1)

Vague Triggers

Medium
Confidence
81% confidence
Finding
The default prompt is broadly framed and lacks scope boundaries, exclusions, or safety qualifiers, which can cause the skill to activate for loosely related requests and drive content generation from user-supplied 'sources' without clarifying trust or verification requirements. In a content-growth and AI-search optimization context, this increases the risk of generating misleading marketing claims, unverified evidence cards, or policy-sensitive promotional material at scale.

Static analysis

No suspicious patterns detected.