Back to skill

Security audit

Shen Nanpeng Perspective V2

Security checks for vulnerabilities and agentic risk

Overview

This is a text-only simulated business-perspective skill with no code or system access, though it may activate broadly and speak in a first-person persona.

Install this only if you want a simulated Shen Nanpeng-style business thinking framework. Treat outputs as roleplay and decision support, not the real person's views or professional financial advice, and be aware it may activate on broad phrases like long-term value or first-principles thinking.

Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (2)

Vague Triggers

Medium
Confidence
90% confidence
Finding
The trigger conditions are broad enough to activate on generic phrases like long-term value or first-principles thinking, which can cause unintended routing to this persona instead of the user’s actual desired capability. In a decision-support skill, that can bias answers, override more appropriate tools, and produce misleading persona-framed guidance in unrelated contexts.

Natural-Language Policy Violations

Low
Confidence
79% confidence
Finding
The skill instructs the agent to respond directly in the persona and use first-person identity, without explicit opt-in for style or locale. While not directly enabling code execution or data exfiltration, this increases the risk of user deception, mistaken attribution, and reduced transparency about whether advice is simulated or authentic.

Static analysis

No suspicious patterns detected.