Back to skill

Security audit

quick-proposal

Security checks for vulnerabilities and agentic risk

Overview

This is a simple text-only proposal-writing skill with no evidence of hidden commands, credential use, persistence, or data exfiltration.

Reasonable to install if you want a lightweight Chinese proposal-writing template. Provide concrete project requirements, budget assumptions, and timeline constraints before using its estimates, and verify any generated costs or schedules before sending them to clients.

Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (1)

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
86% confidence
Finding

The invocation examples are very broad natural-language requests and do not define clear activation boundaries, exclusions, or required context. In an agent environment, this can cause the skill to trigger on loosely related user input and generate proposals in contexts where it was not intended, increasing the chance of inappropriate execution, prompt collisions, or misuse with sensitive project data.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.