Back to skill

Security audit

SEC2 可信溯源服务

Security checks for vulnerabilities and agentic risk

Overview

This is a markdown-only guidance skill for generating SEC2/Phylax provenance-service content, with no code execution, data access, persistence, or hidden installation behavior.

Install this only if you want the agent to produce SEC2/Phylax-branded provenance and traceability solution language. Users should not treat it as legal, regulatory, or official certification guidance, and factual claims about laws, standards, or deployment status should be independently verified before external use.

Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (2)

Vague Triggers

Medium
Confidence
89% confidence
Finding
The activation trigger is defined using broad, generic semantics such as any task involving provenance, fingerprints, AIGC tracing, supply chain tracing, or signature wording. This can cause the skill to be invoked in contexts where only tangential overlap exists, leading the agent to adopt the skill’s persona and guidance unexpectedly and potentially steer outputs beyond the user’s intended scope.

Vague Triggers

Medium
Confidence
84% confidence
Finding
The FAQ states that the skill may be loaded for tasks needing provenance solutions, trusted-chain audit, or AIGC traceability content, but does not clearly define exclusion boundaries. This ambiguity increases the chance of unintended invocation and unnecessary persona/policy injection into broader conversations, which can bias outputs or cause inappropriate reliance on this skill’s framing.

Static analysis

No suspicious patterns detected.