Back to skill

Security audit

装修报价审核

Security checks for vulnerabilities and agentic risk

Overview

This skill is a renovation quote-audit knowledge guide made of Markdown files and does not request unusual access or perform hidden actions.

This appears safe to install for renovation quote review. Be aware that it may activate on broad renovation-budget wording, and avoid sharing unnecessary personal details such as full addresses, phone numbers, contract IDs, or payment information when submitting quote documents for review.

Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (1)

Vague Triggers

Medium
Confidence
88% confidence
Finding
The trigger list contains broad phrases like '报价单', '装修预算', and '装修多少钱' that can match general user queries outside the narrow intent of quote-audit assistance. This can cause the skill to activate unexpectedly, override more appropriate skills, or capture conversations with insufficient context, leading to confusing or low-quality responses rather than direct code-execution risk.

Static analysis

No suspicious patterns detected.