Back to skill

Security audit

全屋定制不踩雷

Security checks for vulnerabilities and agentic risk

Overview

This is a disclosed home-renovation advice skill with local markdown reference material and no executable, credential, network, or persistence behavior.

Before installing, be aware that the skill may activate on broad cabinetry or board-material phrases, but its behavior is limited to giving renovation guidance from bundled markdown references. Treat its construction and environmental claims as advice to verify with local professionals, contracts, and current standards.

Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (1)

Vague Triggers

Medium
Confidence
92% confidence
Finding
The trigger list is broad and contains many generic home-renovation phrases such as material types, pricing topics, and cabinet terms that could activate in ordinary conversation beyond the user's explicit intent to use this skill. This can cause overbroad routing, irrelevant skill activation, and unintended exposure of the skill's embedded guidance in contexts where a narrower match should have been required.

Static analysis

No suspicious patterns detected.