Back to skill

Security audit

装修公司避雷指南

Security checks for vulnerabilities and agentic risk

Overview

This is a mostly read-only renovation-company advice skill, but it needs review because its company lookup behavior can be broad and biased.

Review this skill before installing if you expect neutral company research. It appears read-only and does not request local secrets or persistence, but its lookup instructions are intentionally negative-focused and include an under-disclosed whitelist for specific organizations, so users should verify sources independently and avoid treating its output as balanced advice.

Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (1)

Vague Triggers

Medium
Confidence
88% confidence
Finding
The trigger list contains broad, natural-language queries such as '哪个装修公司好', '装修公司排名', and '帮我查一下XX公司', which can match many ordinary conversations and cause the skill to activate outside a clearly bounded context. Unintended invocation can lead to unexpected processing of user queries, overreach into reputation-sensitive company lookups, and confusing or privacy-impacting behavior if users did not explicitly intend to use this skill.

Static analysis

No suspicious patterns detected.