Back to skill

Security audit

装修合同审核

Security checks for vulnerabilities and agentic risk

Overview

This is a Markdown-only renovation contract review skill with purpose-aligned consumer guidance, though users should redact sensitive contract details before using it.

Before installing, understand that this skill gives practical renovation-contract guidance, not legal advice. Redact names, phone numbers, addresses, ID numbers, signatures, bank/payment details, and sensitive dispute facts before pasting contracts or quotes into an AI chat, and verify legal or regional claims with a qualified local professional when money or litigation is at stake.

Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (4)

Vague Triggers

Medium
Confidence
88% confidence
Finding
The skill description and trigger guidance cast the scope very broadly, including effectively all questions related to装修合同审核 scenarios. Overly broad triggering can cause the skill to activate in ambiguous contexts and override a more appropriate skill or default assistant behavior, increasing the chance of irrelevant, low-quality, or policy-conflicting advice. In this contract-review context, that matters because users may receive domain-specific guidance when asking adjacent legal, financial, or dispute questions the skill explicitly should not fully handle.

Missing User Warnings

Medium
Confidence
91% confidence
Finding
The document explicitly recommends sending full contract text to an AI for review, but provides no caution about exposing personal information, financial terms, addresses, phone numbers, signatures, or other confidential contractual data to third-party AI services. In a contract-review skill, users are especially likely to paste sensitive documents verbatim, so the omission materially increases privacy, confidentiality, and data-handling risk.

Natural-Language Policy Violations

Low
Confidence
98% confidence
Finding
The flagged text uses insulting language ('人渣') to describe a counterparty. This is not a code-execution or data-security issue, but it is a genuine policy/content concern because abusive phrasing can normalize hostility and reduce the professionalism and trustworthiness of the skill output.

Natural-Language Policy Violations

Low
Confidence
97% confidence
Finding
This is another instance of the same insulting wording in user-facing guidance. In the context of a contract-review skill, such language is unnecessary and can create reputational, moderation, or compliance issues even though the underlying advice is about consumer protection.

Static analysis

No suspicious patterns detected.