Back to skill

Security audit

装修避坑顾问

Security checks for vulnerabilities and agentic risk

Overview

This is a markdown-only renovation advice skill with broad but disclosed activation and no code, data access, or privileged behavior.

Install this if you want concise Chinese renovation guidance. Treat the advice as general guidance, verify local code and safety issues with qualified professionals, and note that the artifact includes a small promotional line for a WeChat mini program.

Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (1)

Vague Triggers

Low
Confidence
92% confidence
Finding
The trigger conditions are very broad, using many common renovation-related keywords without clear exclusions or disambiguation. This can cause the skill to activate on loosely related queries and override a more appropriate skill, leading to irrelevant or misleading advice being presented with high confidence.

Static analysis

No suspicious patterns detected.