Back to skill

Security audit

Wang Jianlin Perspective V2

Security checks for vulnerabilities and agentic risk

Overview

This appears to be a Chinese-language persona skill with some overbroad activation wording, but no evidence of hidden commands, credential use, persistence, or data access.

Install only if you want this persona behavior. Be aware that broad triggers may make the assistant adopt the persona during ordinary business discussions; prefer explicit activation phrases and keep normal safety and transparency rules above the roleplay.

Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (3)

Vague Triggers

Medium
Confidence
92% confidence
Finding
The trigger list includes generic business terms like “执行力”, “订单地产”, and “轻资产”, which are broad enough to match ordinary business conversations unrelated to this persona. That can cause unintended activation, leading the assistant to switch into a forceful roleplay mode without clear user intent and potentially degrade reliability or override expected assistant behavior.

Vague Triggers

Medium
Confidence
90% confidence
Finding
The instruction to respond directly in-character whenever the skill is activated lacks tight activation and deactivation boundaries. In practice, ambiguous activation criteria combined with mandatory role adherence can cause the model to remain in persona unexpectedly, suppress meta-level safety behavior, or answer in a misleading first-person identity framing when the user did not clearly consent.

Natural-Language Policy Violations

Medium
Confidence
84% confidence
Finding
The skill is authored entirely around a Chinese-language persona style and instructs direct in-character responses without offering language choice or explicit user opt-in. This is less a classic security exploit than a control/UX safety issue: it can reduce user agency, create confusion, and increase the chance of unwanted persona injection in multilingual contexts.

Static analysis

No suspicious patterns detected.