Back to skill

Security audit

行业分析·生态图谱

Security checks for vulnerabilities and agentic risk

Overview

This skill is a coherent industry ecosystem report generator that uses web research and local report/session files in ways that match its stated purpose.

Before installing, expect the skill to perform web research, create or overwrite an ecosystem Markdown report under output/{industry-slug}, and update the local session.json workflow state. Review the generated sources and report content because third-party web pages may be incomplete, stale, or misleading.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Findings (3)

Missing User Warnings

Low
Category
Not specified by scanner
Confidence
94% confidence
Finding

The skill writes output/{industry-slug}/02-ecosystem.md and updates session.json, but the description does not clearly warn users that running it mutates local files and workflow state. This can lead to unintended overwrites, stale state transitions, or users invoking the skill under the mistaken assumption that it is read-only.

Content

No source excerpt is available for this finding.

Missing User Warnings

Low
Category
Not specified by scanner
Confidence
92% confidence
Finding

The workflow instructs the agent to perform web_search and webfetch, but the skill description does not warn that it retrieves external content. This matters because fetched web content is untrusted and can introduce prompt-injection attempts, inaccurate data, privacy issues, or unexpected network activity during execution.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
94% confidence
Finding

This markdown template forces a specific language/locale in its natural-language instructions and examples. Under the policy, language constraints should either be optional for the user or clearly documented as region- or compliance-specific.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.