Back to skill

Security audit

AI 情报车间

Security checks across malware telemetry and agentic risk

Overview

This skill is a disclosed content-research workflow that uses web search and writes generated files only within its stated AI industry-analysis purpose.

Installers should expect this skill to browse the web and create local markdown outputs for social/content workflows. Use it for public or non-confidential industry research, review sources before publishing, and be aware that broad AI-impact questions may trigger it even without naming the skill.

Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (4)

Missing User Warnings

Medium
Confidence
84% confidence
Finding
The README advertises automatic web retrieval and generation of publishable content, but does not warn users that prompts, retrieved data, or industry inputs may be transmitted to external services or incorporated into saved output. In an agent-skill context, this can lead to unintentional disclosure of sensitive business topics, personal data, or regulated information because users may assume the workflow is local and low-risk.

Vague Triggers

Medium
Confidence
90% confidence
Finding
The trigger list includes broad natural-language examples like 'AI 对会计有什么影响' and 'AI 会冲击教育吗', which can cause the skill to activate during ordinary conversation rather than only on explicit invocation. That increases the chance of unintended web access, content generation, and file-writing behavior without the user clearly intending to run this workflow.

Vague Triggers

Medium
Confidence
88% confidence
Finding
The manifest description embeds sweeping trigger phrases for analyzing AI's impact on virtually any industry, without strong invocation boundaries. In systems that use description text for routing, this can over-match general user requests and dispatch the skill unexpectedly, expanding the skill's reach beyond deliberate user intent.

Vague Triggers

Medium
Confidence
94% confidence
Finding
The description contains broad mandatory-trigger language such as 'must use this skill' for common requests about AI's impact on an industry. That can cause over-selection for ordinary user intents, routing unrelated or only partially related requests into this skill and potentially triggering unnecessary web access, content generation, or file-writing behavior without clear user intent. In this context, the skill is not directly executing dangerous system actions, but the broad activation scope increases the chance of unintended invocation and downstream misuse of generated outputs.

VirusTotal

64/64 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.