Back to skill

Security audit

一人公司办企业全流程(OPC)

Security checks for vulnerabilities and agentic risk

Overview

This is a documentation-only company formation guide with no code execution, credential use, persistence, or hidden data access.

Installers should treat this as a static reference guide, not legal, accounting, or tax advice. Verify current rules with the relevant market regulator, tax authority, accountant, or lawyer before acting, especially because filing requirements and tax policies can change.

Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Findings (2)

Natural-Language Policy Violations

Medium
Confidence
95% confidence
Finding
The file explicitly mandates a specific branding signature for all public releases, which can override a user's preferred identity or attribution style without opt-in. In an agent skill ecosystem, forced branding can mislead users about authorship, create compliance issues for downstream redistributors, and act as an instruction that competes with higher-priority system or user preferences.

Natural-Language Policy Violations

Medium
Confidence
95% confidence
Finding
The skill content is written entirely in Chinese and effectively constrains the agent to respond in Chinese without checking the user's language preference. This can reduce usability, cause misunderstandings for non-Chinese-speaking users, and override higher-level expectations about adapting to user input language, though it does not directly create code-execution or data-exfiltration risk.

Static analysis

No suspicious patterns detected.