Back to skill

Security audit

Opc Os Core

Security checks for vulnerabilities and agentic risk

Overview

This skill is mostly coherent, but it gives autonomous agents ongoing publishing and cloud-document fallback authority without enough approval and data-handling boundaries.

Install only if you are comfortable configuring autonomous agents, scheduled jobs, local work directories, and external document or publishing services. Before use, require manual approval for any public post, cloud upload, skill publish, or republish; restrict Tencent/Feishu fallback to non-sensitive or approved workspaces; and review cron payloads before enabling them.

Vulnerability Patterns
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (2)

Missing User Warnings

Medium
Confidence
93% confidence
Finding
Recommending Tencent Docs / Feishu Docs as a fallback communication channel without any privacy or data-classification guidance can lead agents to place sensitive company data into third-party platforms with different access controls, retention policies, and jurisdictional exposure. In this skill context, multiple autonomous departments may exchange legal, finance, sales, or governance content, so an undocumented cloud fallback increases the risk of inadvertent data leakage.

Missing User Warnings

Medium
Confidence
77% confidence
Finding
The monthly maintenance job authorizes autonomous republishing of all published skills whenever local versions differ, which creates a system-impacting change path without any approval gate or integrity verification. In this skill context, automated publication affects downstream consumers and could propagate accidental or malicious local modifications at scale.

Static analysis

No suspicious patterns detected.