Back to skill

Security audit

Zhongguancun Signal Monitor

Security checks for vulnerabilities and agentic risk

Overview

This is a markdown-only workflow for public company signal research, with no code, credential access, persistence, or hidden actions.

Install only if you want the agent to run public web searches about listed companies and produce collaboration recommendations. For best control, provide a company list, time window, industry scope, and Top N count, and ask the agent to confirm before deeper follow-up research.

Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (2)

Vague Triggers

Medium
Confidence
93% confidence
Finding
The skill description contains broad natural-language triggers such as scanning opportunities, monitoring company activity, finding partners, and asking which companies are worth contacting this week. These can overlap with ordinary conversation and cause unintended skill activation, potentially launching external monitoring/research behavior when the user did not explicitly request this skill.

Vague Triggers

Low
Confidence
82% confidence
Finding
The cross-skill handoff rule uses a vague phrase like '调研一下这家' to trigger another skill without clear confirmation gates or scope checks. Ambiguous handoffs can cause unintended chaining into deeper research workflows, increasing the chance of over-collection, surprise tool use, or execution of the wrong skill based on casual user phrasing.

Static analysis

No suspicious patterns detected.