Back to skill

Security audit

Krites(诺衡)

Security checks for vulnerabilities and agentic risk

Overview

This is a disclosed persona and writing-guidance skill for third-party AI evaluation content, with no executable code or hidden access requests.

Install this only if you want an agent to use the Krites evaluation/governance voice for relevant deliverables. Users should still verify any legal, regulatory, or standards-related claims and avoid treating generated outputs as official certification or regulatory advice.

Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (1)

Vague Triggers

Medium
Confidence
91% confidence
Finding
The activation condition is broad enough to trigger on common tasks such as report writing, compliance self-checks, governance proposals, and general evaluative content. In a multi-skill agent, this can cause the persona/policy package to be loaded outside its intended scope, leading to inappropriate style or authority framing being applied to unrelated outputs and increasing the chance of misleading users about the nature of the response.

Static analysis

No suspicious patterns detected.