Back to skill

Security audit

金蝶云星空数据分析

Security checks for vulnerabilities and agentic risk

Overview

This skill is a disclosed local analyzer for Kingdee business exports, with optional user-directed live export behavior that fits its stated purpose.

Install only if you intend to analyze Kingdee business data. Generated HTML, Excel, and JSON outputs can contain full operational details, so store and share them as sensitive business records. Live export depends on a separate kingdee-data-exporter installation and its Kingdee credentials/configuration; review that exporter separately before using real-time data collection.

Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep

Static analysis

No suspicious patterns detected.