Back to skill

Security audit

Wang Chuanfu Perspective V2

Security checks for vulnerabilities and agentic risk

Overview

This appears to be a persona-style business strategy skill with disclosure issues, but no evidence of hidden code, credential use, persistence, data access, or unsafe actions.

Before installing, understand that this skill may steer normal business discussions into a Wang Chuanfu-style persona if broad trigger phrases are used. Treat outputs as a synthesized roleplay perspective, not statements from the real person or authoritative investment advice.

Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
Findings (3)

Intent-Code Divergence

Medium
Confidence
95% confidence
Finding
The skill explicitly says it is not Wang Chuanfu personally, then instructs the agent to answer in first person as if it were him. This creates identity misrepresentation and can mislead users into treating outputs as authoritative personal viewpoints rather than a synthesized roleplay framework, especially in strategy or investment discussions.

Vague Triggers

Medium
Confidence
92% confidence
Finding
The activation rules allow triggering on very broad phrases like ‘技术为王’, ‘垂直整合怎么做’, and other generic business concepts. This can cause unintended activation during ordinary discussion, leading the model to shift persona or decision style without clear user intent.

Vague Triggers

Medium
Confidence
94% confidence
Finding
The trigger list near the end repeats broad topical keywords without any gating or exclusion logic. Because these phrases are common in business and engineering conversations, the skill may activate unexpectedly and override normal assistant behavior or user expectations.

Static analysis

No suspicious patterns detected.