Back to skill

Security audit

Zhongguancun Industry Research

Security checks for vulnerabilities and agentic risk

Overview

This is a low-risk Chinese-language research skill for public company partnership analysis, with no executable code or hidden access.

Install if you want a Chinese-language assistant for public partnership and industry research. Be aware it may activate on broad company-research prompts and may use web/search results; avoid providing confidential internal material unless you intend it to be included in the analysis.

Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (2)

Vague Triggers

Medium
Confidence
91% confidence
Finding
The trigger text includes broad natural-language phrases like “帮我看看XX公司能不能合作” and “调研一下XX”, which are common user requests and can cause the skill to activate in situations beyond its intended enterprise partnership-research scope. Over-broad invocation increases the chance of unintended tool use, irrelevant data collection, or routing users into a specialized workflow without clear consent.

Natural-Language Policy Violations

Medium
Confidence
82% confidence
Finding
The skill is written to operate in Chinese and does not offer any user-language negotiation, which can force responses into a language the user did not request. This is primarily a safety/UX issue rather than a direct security exploit, but it can still cause misunderstanding of research results, cooperation recommendations, or generated agendas.

Static analysis

No suspicious patterns detected.