Back to skill

Security audit

论文报告验真教程

Security checks for vulnerabilities and agentic risk

Overview

This skill is a disclosed, user-guided tutorial for checking paper report authenticity, with no hidden execution, persistence, or credential collection.

Before entering report details, confirm the destination is the correct official page for your report brand. Do not provide account passwords, full reports, or CAPTCHA values to the agent, and treat a successful verification as proof of a matching record only, not proof that the paper meets academic requirements.

Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (1)

Vague Triggers

Medium
Confidence
84% confidence
Finding
The default prompt is broadly framed and appears to instruct the agent to always provide verification guidance, including brand identification and step-by-step handling, without explicit trigger boundaries or safety exclusions. In a system that may invoke skills based on semantic matching, this can cause over-activation on loosely related report or document queries, increasing the chance of irrelevant instruction delivery, user confusion, or steering users to a fixed verification endpoint even when the report brand differs.

Static analysis

No suspicious patterns detected.