Back to skill

Security audit

INS 情绪内容(含Meme)

Security checks for vulnerabilities and agentic risk

Overview

This is a markdown-only Instagram marketing copy skill with broad triggers but no executable code, credential access, persistence, or hidden data handling.

Install this if you want a FridayParts-focused Instagram content assistant. Consider narrowing the triggers in environments with many writing skills, and expect the skill to default to English unless you edit that instruction.

Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (5)

Vague Triggers

Medium
Confidence
87% confidence
Finding
The trigger list contains broad everyday terms like 'instagram', 'meme', and 'reel' that can cause the skill to activate in many unrelated conversations. Over-broad invocation increases the chance of prompt hijacking at the routing layer, accidental brand-content generation when the user wanted something else, or unintended exposure of this skill's internal instructions.

Vague Triggers

Medium
Confidence
83% confidence
Finding
The 'Use when' description is vague and broad, lacking clear boundaries for when this skill should or should not run. Ambiguous routing criteria can lead to unintended invocation, causing the model to apply this brand-specific persona and output format in contexts where the user did not request it.

Vague Triggers

Medium
Confidence
91% confidence
Finding
The trigger list contains broad, common terms such as "meme," "reel," and "段子," which can cause the skill to activate for many unrelated requests. Overbroad invocation increases the chance of accidental routing, unexpected behavior, and policy bypass of more appropriate skills or user intent handling.

Vague Triggers

Medium
Confidence
87% confidence
Finding
The "Use when" guidance is broad and open-ended, covering generic Instagram content, memes, reels, and jokes without clear exclusion criteria. This ambiguity can lead to unintended invocation in contexts outside industrial/mechanical marketing, causing misrouting and potentially inappropriate or low-quality outputs.

Overly Broad Trigger

Low
Category
Trigger Abuse
Confidence
84% confidence
Finding
The trigger '段子' is short and semantically broad, so it may match many casual requests involving jokes or punchlines that are unrelated to this brand-specific Instagram skill. That can lead to accidental invocation and inappropriate steering toward FridayParts marketing content in unrelated conversations.

Static analysis

No suspicious patterns detected.