Back to skill

Security audit

文润

Security checks for vulnerabilities and agentic risk

Overview

This is a local Chinese writing-analysis skill with no network use, persistence, credential access, or destructive behavior.

Before installing, note that broad Chinese writing prompts such as polishing or text optimization may invoke this skill. Use it for local analysis of text you are comfortable displaying in the terminal output, since findings include excerpts of the analyzed content.

Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (1)

Vague Triggers

Medium
Confidence
82% confidence
Finding
The trigger keywords include broad terms like '润色', '自然度', and '文字优化', which are common in ordinary writing workflows and may cause the skill to activate unintentionally. Unintended activation can expose user text to processing they did not mean to invoke, increasing the chance of confusing behavior or inappropriate handling of sensitive content.

Static analysis

No suspicious patterns detected.