Back to skill

Security audit

亿欧 Demo 转技术方案

Security checks for vulnerabilities and agentic risk

Overview

This skill is a documentation helper that turns Chinese-language demo or requirement descriptions into technical planning documents, with no executable code or hidden system access found.

Install this if you want a Chinese-language workflow for converting demos or requirements into technical planning documents. Review outputs carefully because the skill is designed to infer fields, APIs, data ownership, and tasks from incomplete inputs, although it requires those inferences to be marked for confirmation.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (6)

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
83% confidence
Finding

The entire skill description and invocation prompt are written only in Chinese, and the quick-start prompt instructs a fixed response style without offering the user a language or locale option. Under the stated policy, forcing a specific language without opt-in is a natural-language policy violation unless the locale constraint is explicitly documented and justified.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
89% confidence
Finding

The trigger phrases are broad enough to match common documentation and product-planning requests, which can cause the skill to activate outside its intended scope. This increases the chance of context hijacking or accidental routing of unrelated user tasks into a rigid workflow that infers requirements, interfaces, and data structures from incomplete inputs.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

This markdown template is entirely written in Chinese and provides no indication that language selection is optional or that the template is specifically intended for a Chinese-language or region-specific context. Under the policy, forcing a specific language without user opt-in is a natural-language policy violation.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
95% confidence
Finding

This JSON template includes natural-language values in Chinese (for example, the source field options) while providing no indication that the skill is intended only for Chinese-speaking users or that language selection is configurable. That can violate a language/locale policy requiring user choice or explicit justification for a fixed locale.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
93% confidence
Finding

The status field uses Chinese-only options, which forces a specific language in the template output. Because the file does not document a region-specific scope or offer user language choice, this is a natural-language policy concern.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
91% confidence
Finding

Fields such as level, owner, and type define Chinese-only allowed values across the template. In the absence of explicit locale justification or opt-in, the template effectively mandates one language, which may conflict with organizational language-choice policy.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.