Back to skill

Security audit

ssot-content-management

Security checks for vulnerabilities and agentic risk

Overview

This is a low-risk methodology skill for SSOT content management, with only minor routing-scope concerns.

Installers should be aware that this skill may be routed for broad content-management prompts because of generic activation terms. It appears safe as an advisory method skill, but publishers should narrow triggers to SSOT-specific phrases to reduce accidental activation.

Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (3)

Vague Triggers

Medium
Confidence
84% confidence
Finding
The trigger keywords are extremely generic terms like "content" and "management", which can cause this skill to be invoked for many unrelated prompts. In an agent ecosystem, overly broad auto-discovery or routing can misapply the skill's instructions or output in contexts where it was not intended, increasing confusion and expanding attack surface for prompt-routing abuse.

Vague Triggers

Medium
Confidence
91% confidence
Finding
The manifest description contains extensive trigger phrases such as '减少变更', 'SSOT', '改一处生效', and other broad content-management concepts, making activation likely for many ordinary knowledge, documentation, or workflow questions. Overly broad routing can cause this skill to be invoked outside its narrow intended scope, leading to inappropriate guidance, prompt overshadowing, or interference with more relevant skills.

Natural-Language Policy Violations

Medium
Confidence
84% confidence
Finding
The manifest is written to operate in Chinese and uses Chinese-only trigger and behavior framing without indicating user language negotiation or a justified locale limitation. This can cause the skill to respond in an unexpected language or capture requests from users who did not ask for Chinese output, degrading safety, usability, and correct intent routing.

Static analysis

No suspicious patterns detected.